Privacy policy
Privacy Policy
Last updated: 30/09/2025
1. Data Controller
The website www.kometeatelier.com is operated by SNR Society OÜ, a private limited company governed by Estonian law, registered with the Estonian Commercial Register under number 17333898, whose registered office is located at Sepapaja tn 6, 15551 Tallinn, Estonia (hereinafter referred to as “Komète Atelier”).
Primary contact: contact@kometeatelier.com
2. Data Collected
We collect and process the following categories of personal data:
-
Identification data (name, surname, address, email, phone number)
-
Order and billing information
-
Payment data (via secure service providers: Shopify Payments, Klarna, PayPal, Stripe)
-
Browsing data and cookies (IP address, pages visited, preferences)
-
Data from forms (contact, returns, customization requests)
-
Data from customer accounts and loyalty or subscription programs, if applicable
No sensitive data is collected.
3. Purposes and Legal Bases
Data processing is based on the following legal grounds:
-
Contract performance: order management, delivery, returns, customer service.
-
Legal obligation: invoicing, accounting, and tax compliance.
-
Consent: newsletter subscription, personalized offers, analytical and marketing cookies.
-
Legitimate interest: fraud prevention, website improvement, internal statistics, payment security.
4. Data Retention Periods
-
Billing and order data: 10 years (legal requirement).
-
Customer service data: 3 years after the last contact.
-
Marketing data (newsletter, promotions): until consent is withdrawn or after 3 years of inactivity.
-
Cookies: maximum duration of 13 months.
5. Subprocessors and Data Recipients
Your data may be shared only with authorized service providers, including:
-
Shopify (website hosting and e-commerce platform)
-
Shopify Payments / Stripe / Klarna / PayPal (secure payment processing)
-
Google Analytics / Meta Pixel (analytics and marketing, with consent)
-
Logistics and shipping providers (La Poste, Colissimo, Chronopost, or other logistics partners)
-
Email marketing tools (e.g., Klaviyo, Mailchimp) used only when you subscribe to our newsletter
All these service providers comply with the GDPR and guarantee the confidentiality and security of the data processed on behalf of Komète Atelier.
6. Data Transfers Outside the European Union
Some providers (Shopify, Google, Meta, PayPal, Klaviyo) may transfer data outside the EU, particularly to the United States.
Such transfers are governed by:
-
Standard Contractual Clauses (SCCs) approved by the European Commission, or
-
the EU–US Data Privacy Framework, or
-
equivalent mechanisms (UK IDTA for the United Kingdom).
No data is transferred to countries without an adequate level of protection unless appropriate safeguards are in place in accordance with the GDPR.
7. Data Security
Komète Atelier implements appropriate technical and organizational measures to protect your personal data, including:
-
SSL encryption of communications,
-
Secure data storage,
-
Restricted access to authorized personnel only,
-
Regular backups,
-
Periodic audits of service providers.
No payment or banking data is stored on our servers.
8. User Rights
In accordance with Regulation (EU) 2016/679 (GDPR), the UK GDPR, and Estonian data protection laws, you have the following rights:
-
Right of access, rectification, and erasure
-
Right to object or restrict processing
-
Right to data portability
-
Right to withdraw your consent at any time
To exercise your rights:
-
Use the contact form on the website, or
-
Email: contact@kometeatelier.com
Supervisory authorities:
-
CNIL (France) – www.cnil.fr
-
ICO (United Kingdom) – ico.org.uk
-
Estonian Data Protection Inspectorate (AKI) – www.aki.ee
9. Data Relating to Minors
Komète Atelier does not knowingly collect personal data from minors under 15 years old (France) or 16 years old (EU/UK).
If such data is collected without parental consent, it will be deleted immediately upon notification.
10. Cookies
This website uses cookies necessary for its operation, as well as statistical and marketing cookies subject to the user’s prior consent.
Cookie preferences can be managed at any time via the cookie consent banner or your browser settings.
Cookie consent validity: 13 months.
11. Changes to This Policy
This Privacy Policy may be updated at any time to reflect legal, technical, or organizational changes.
The date of the last update is indicated at the top of this document.