Privacy Policy
This policy applies to the website https://www.easy-occupational-risk-assessment.com
(the “Site”) operated by Document Unique Facile (the “Company”, “we”). It describes how your personal data are collected and processed in accordance with Regulation (EU) 2016/679 (GDPR).
1. Identity and contact details of the organisation (data controller).
Controller: Document Unique Facile, sole-trader business operated by Thony Maufay.
Address: 30 Rue des Écouvilliers, 78700, Conflans-Sainte-Honorine.
SIREN No.: 841918352.
Primary contact (data protection and rights requests): easyoccupationalriskassessment@gmail.com
Telephone: 01 71 52 64 20.
2. Purposes (what the collected data will be used for).
Your data are never sold, given away, transferred or exchanged in return for any remuneration. We process your data for:
-
Order management: online purchase of “Document Unique” (DUERP) files, delivery of downloadable files, after-sales service and support.
-
Invoicing and accounting: issuing invoices to the customer, internal company accounting.
-
Customer relations: responding to your requests (contact forms, email, live chat), understanding customer needs by consulting the exchange history.
-
Improving the Site and audience measurement: anonymised/aggregated statistics, performance analysis of the Site (mainly monitoring visitor numbers via Google Analytics, after consent via the cookie banner).
-
Prospecting and communications: sending information about our products/services (email, requests to leave a review, abandoned-basket reminders) if you have consented or in compliance with applicable rules.
3. Legal basis for processing.
Depending on the purpose:
-
Performance of a contract (Art. 6(1)(b) GDPR): order placement, delivery of digital products, customer service.
-
Legal obligation (Art. 6(1)(c)): accounting obligations, retention of invoices.
-
Consent (Art. 6(1)(a)): placement of non-essential cookies (analytics/marketing), website form, publication of testimonials and reviews.
-
Legitimate interests (Art. 6(1)(f)): Site security, fraud prevention, improvement of our website, prospecting within legal limits. You may object to such processing for reasons relating to your particular situation.
4. Mandatory or optional nature of providing data and consequences of not providing them.
-
Mandatory: the data requested on the checkout page are necessary for order placement, invoicing and delivery (e.g. name, email, company address, payment information via our payment providers). If not provided, the order cannot be placed.
-
Optional: marketing cookies, functional cookies and analytics cookies can be declined via the cookie banner. Refusing them does not prevent purchase, but may limit certain features, as detailed below:
_ Essential cookies (strictly necessary) — always active, not subject to consent: security, load balancing, session, basket and payment. Without them, the Site cannot function correctly.
_ Functional cookies — optional: remembering your preferences (basket, sign-in). If refused, some preferences will not be saved and certain features may be degraded.
_ Analytics cookies (audience measurement) — optional: visit statistics (for example Google Analytics). If refused, we will not perform personalised audience measurement; this does not affect purchase.
_ Marketing cookies — optional: advertising personalisation and remarketing. If refused, you will receive less personalised content; no impact on purchase.
-
5. Recipients or categories of recipients of the data.
Access is limited, on a need-to-know basis, to:
-
Internal team: Thony Maufay.
-
Site hosting: Wix (operation of the Site).
-
Payment providers: Stripe and PayPal.
-
Email: Google (Gmail).
-
Live chat: Wix.
-
Audience measurement: Google Analytics and Wix, triggered only after consent.
We may be required to disclose certain information if requested by an administrative, tax, judicial or supervisory authority.
-
6. Data retention period (or criteria used to determine it).
We keep data for limited and proportionate periods:
_ Invoices and related data: minimum 10 years (legal obligation).
_ Support (emails, forms, chat): 3 years from the last exchange.
_ Prospecting (newsletter/reminders): 3 years from the last contact or withdrawal of consent.
_ Cookies: 13 months.
After these periods, data are deleted, anonymised or archived in accordance with legal obligations.
-
7. Rights of data subjects.
You have the following rights, within the conditions and limits set by the law:
-
Right of access to your data.
-
Right to rectification of inaccurate or incomplete data.
-
Right to erasure (“right to be forgotten”) where the conditions are met.
-
Right to restriction of processing.
-
Right to object to processing based on legitimate interests (including prospecting) at any time.
-
Right to withdraw consent at any time for processing based on consent (e.g. cookies, newsletter), without retroactive effect.
-
Right to data portability for data you have provided to us, where processing is based on consent or contract and carried out by automated means.
-
Post-mortem directives on the fate of your data after your death.
To exercise your rights: contact us by email or by post, specifying your identity and request. We may ask you for proof of identity in case of reasonable doubt (e.g. contact from a new email address unknown to us). You will receive a response as soon as reasonably possible.
-
8. Contact details of the Data Protection Officer (DPO) or point of contact.
We do not have a DPO. For any questions relating to data protection or to exercise your rights, you can contact: easyoccupationalriskassessment@gmail.com.
-
9. Right to lodge a complaint with the CNIL.
If, after contacting us, you consider that your rights are not being respected, you may lodge a complaint with the CNIL (Commission Nationale de l’Informatique et des Libertés).