Privacy Policy
Zynavo ("we", "our", or "us") is committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and French data protection laws. This Privacy Policy explains how we collect, use, and protect your personal data when you interact with our website and services.
1. Data Controller
The data controller responsible for your personal data is:
Data Controller
Zynavo
27 Rue de la Fleur de Sel
44740 Batz-sur-Mer, France
Email: contact@zynavo.org
Phone: +33 2 40 23 92 10
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer to oversee our privacy practices. You may contact our DPO directly for any data protection inquiries:
Data Protection Officer
Email: dpo@zynavo.org
Postal: DPO, Zynavo, 27 Rue de la Fleur de Sel, 44740 Batz-sur-Mer, France
3. Personal Data We Collect
We collect the following categories of personal data:
3.1 Information You Provide Directly
- Contact information: Name, email address, phone number, postal address
- Professional information: Business name, professional affiliation, job title
- Inquiry content: Messages, questions, and order requests you submit through our forms
- Correspondence: Records of communications with our team
3.2 Information Collected Automatically
- Technical data: IP address, browser type, device type, operating system
- Usage data: Pages visited, time spent on pages, navigation paths
- Cookie data: Information collected through cookies and similar technologies (see our Cookie Policy)
4. Legal Basis for Processing
We process your personal data under the following legal bases as defined by Article 6 of the GDPR:
- Consent (Art. 6(1)(a)): For marketing communications and non-essential cookies
- Contractual necessity (Art. 6(1)(b)): To process orders and respond to inquiries
- Legal obligation (Art. 6(1)(c)): To comply with tax, accounting, and regulatory requirements
- Legitimate interests (Art. 6(1)(f)): For website security, fraud prevention, and business analytics
5. How We Use Your Data
We use your personal data for the following purposes:
- Processing and fulfilling your orders and inquiries
- Communicating with you about your orders, including seasonal allocations
- Sending marketing communications (only with your explicit consent)
- Improving our website, products, and services
- Complying with legal and regulatory obligations
- Protecting against fraud and unauthorized activity
6. Third-Party Processors
We share your data with the following categories of third-party processors:
6.1 Hosting Provider
Our website is hosted by OVHcloud (France), which processes technical data necessary for website operation. OVHcloud is GDPR-compliant and stores data within the European Union.
6.2 Analytics
We use Google Analytics 4 to understand how visitors interact with our website. This service processes anonymized usage data. You may opt out through our cookie preferences.
6.3 Email Services
We use Brevo (formerly Sendinblue) for email communications. Brevo is a French company compliant with GDPR requirements.
7. International Data Transfers
Your data is primarily stored and processed within the European Economic Area (EEA). When data is transferred outside the EEA (e.g., to Google LLC for analytics), we ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The EU-US Data Privacy Framework for applicable US providers
8. Data Retention
We retain your personal data only as long as necessary:
- Inquiry data: 3 years from the last contact
- Order records: 10 years (French commercial law requirement)
- Marketing consent: Until withdrawal of consent
- Technical logs: 12 months
9. Your Rights Under GDPR
As a data subject, you have the following rights:
9.1 Right of Access (Article 15)
You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data.
9.2 Right to Rectification (Article 16)
You may request correction of inaccurate personal data or completion of incomplete data.
9.3 Right to Erasure — "Right to be Forgotten" (Article 17)
You may request deletion of your personal data when:
- The data is no longer necessary for its original purpose
- You withdraw consent (where consent was the legal basis)
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Erasure is required by law
Exceptions: We may retain data when necessary for legal claims, public health, archiving, or legal obligations.
9.4 Right to Restriction (Article 18)
You may request restriction of processing in certain circumstances, such as when contesting data accuracy.
9.5 Right to Data Portability (Article 20)
You may receive your personal data in a structured, commonly used format and transmit it to another controller.
9.6 Right to Object (Article 21)
You may object to processing based on legitimate interests or for direct marketing purposes.
9.7 Rights Related to Automated Decision-Making (Article 22)
We do not engage in automated decision-making or profiling that produces legal effects concerning you.
10. Exercising Your Rights
To exercise any of your rights, please contact our Data Protection Officer:
- Email: dpo@zynavo.org
- Subject line: "GDPR Rights Request — [Your Request Type]"
We will respond to your request within 30 days. In complex cases, we may extend this period by an additional 60 days, with notification.
11. Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the French supervisory authority:
Supervisory Authority
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy, TSA 80715
75334 Paris CEDEX 07, France
Website: www.cnil.fr
12. Security Measures
We implement appropriate technical and organizational measures to protect your personal data, including:
- SSL/TLS encryption for all data transmission
- Secure access controls and authentication
- Regular security assessments and updates
- Staff training on data protection
- Physical security at our premises
13. Children's Privacy
Our website is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children.
14. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "Last updated" date. For significant changes, we will provide prominent notice.
15. Contact Us
For any questions about this Privacy Policy or our data practices, please contact us:
General Inquiries
Email: contact@zynavo.org
Phone: +33 2 40 23 92 10
Address: 27 Rue de la Fleur de Sel, 44740 Batz-sur-Mer, France