PRIVACY POLICY
Updated on January 25, 2026
PREAMBLE
The purpose of this Privacy Policy is to inform users of the www.tresseparis.com website (hereinafter the "Site") of the commitments made by TRESSE PARIS to ensure the protection of their personal data.
The collection and processing of your data are subject to the General Data Protection Regulation (GDPR) and the French "Informatique et Libertés" Law.
1. DATA CONTROLLER
The data controller is the company:
TRESSE PARIS (SAS)
23bis avenue de la Motte-Picquet - 75007 PARIS (France)
RCS PARIS 888 518 255
Data Protection Officer Email: hello@tresseparis.com
2. COLLECTED DATA
TRESSE PARIS ensures that it only collects data strictly necessary for the declared purposes ("data minimization").
We are likely to collect:
- Identity Data: Surname, first name.
- Contact Data: Email, phone number, shipping and billing postal address.
- Financial Data: Order history (banking data is processed directly by our secure payment providers; TRESSE PARIS does not store your full card number).
- Connection Data: IP address, browser type, cookies.
- Sensitive Data (Health/Allergies): TRESSE PARIS does not solicit any medical data. However, if you spontaneously communicate information regarding an allergy or skin reaction (via Customer Service or a review), this data will be treated with the strictest confidentiality and solely for the management of your claim.
3. PURPOSES AND LEGAL BASIS
Your data is processed for the following reasons:
- Contract Execution (Order): Order management, delivery, invoicing, customer service.
- Legal Obligation: Accounting, GDPR rights management.
- Consent: Sending the Newsletter (if you have subscribed), depositing certain cookies.
- Legitimate Interest: Site improvement, statistics, fraud prevention, responding to contact requests.
4. RETENTION PERIOD
- Customer Data: 3 years from the end of the commercial relationship (last order).
- Prospect Data (Newsletter): 3 years from the last contact or subscription.
- Accounting Data (Invoices): 10 years (legal obligation).
- Cookies: 13 months maximum.
5. DATA RECIPIENTS
Your data is exclusively intended for TRESSE PARIS. However, it may be transmitted to our subcontractors acting strictly on our behalf:
- Hosting: PlanetHoster (Canada / France).
- Logistics: Carriers (La Poste, Mondial Relay) for delivery.
- Payment: Banking providers (Stripe, PayPal, Bank).
- Marketing: Emailing tools (e.g., Klaviyo, Mailchimp).
TRESSE PARIS prohibits selling or renting your data to third parties for commercial purposes.
6. TRANSFER OUTSIDE THE EUROPEAN UNION
Some of our service providers, notably our host PlanetHoster (headquartered in Canada), may process data outside the EU.
Canada benefits from an adequacy decision from the European Commission, guaranteeing a level of protection equivalent to the GDPR. For other potential transfers (e.g., US marketing tools), TRESSE PARIS ensures the implementation of Standard Contractual Clauses (SCCs) validated by the European Commission.
7. YOUR RIGHTS
In accordance with the GDPR, you have the following rights regarding your data:
- Right of access, rectification, and erasure (right to be forgotten).
- Right to restriction of processing and data portability.
- Right to object (particularly for the newsletter).
- Right to define the fate of your data after your death.
To exercise these rights, contact us at: hello@tresseparis.com (proof of identity may be requested in case of reasonable doubt about your identity).
If you believe that your rights are not being respected, you can file a complaint with the CNIL (www.cnil.fr).
8. COOKIES
During your navigation, cookies may be deposited on your terminal (computer, mobile).
Some are necessary for the site's operation (shopping cart), others (Google Analytics audience measurement, Facebook Pixel advertising) require your consent.
You can manage your cookie preferences at any time via the cookie management module present on the Site or via your browser settings.
9. SECURITY
TRESSE PARIS implements all necessary technical and organizational measures (HTTPS encryption, complex passwords, restricted access) to protect your data against loss, theft, or unauthorized access.