Privacy Policy

Privacy policy

Compliant with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and with French Act No. 78-17 of 6 January 1978 as amended, on information technology, data files and civil liberties.

1. Data controller

The controller of the personal data collected on the johya.com website is:

JOHYA, SAS, 44 rue Rennequin, 75017 Paris

Contact: administratif@johya.com

2. Data collected

In connection with the use of the site and the purchases made, JOHYA may collect the following categories of data:

  • Identification data: surname, first name, date of birth where applicable
  • Contact data: postal address, email address, telephone number
  • Order data: products purchased, amounts, history
  • Payment data: processed directly by the payment provider (JOHYA does not store bank card numbers)
  • Connection data: IP address, logs, browsing data
  • AML/CFT data: for transactions subject to due diligence obligations, a copy of an identity document, proof of address, proof of the origin of funds

3. Purposes of processing

The data is collected for the following purposes:

  • Management of orders, delivery and after-sales service
  • Management of the customer account
  • Invoicing and bookkeeping
  • Compliance with legal obligations (accounting, AML/CFT, taxation)
  • Sending commercial information and the newsletter (subject to consent)
  • Improvement of the site and usage statistics
  • Fraud prevention

4. Legal bases

The processing operations rest on the following legal bases:

  • Performance of the contract of sale (Article 6.1.b GDPR) for order management
  • Legal obligation (Article 6.1.c GDPR) for accounting, tax and AML/CFT obligations
  • Consent (Article 6.1.a GDPR) for the newsletter and certain non-essential cookies
  • Legitimate interest (Article 6.1.f GDPR) for fraud prevention and improvement of the site

5. Recipients of the data

The data collected is intended for JOHYA and may be passed on to:

  • Shopify International Limited, host of the site and e-commerce provider
  • The payment providers (subprocessors of Shopify Payments)
  • The carriers responsible for delivery
  • JOHYA's accounting firm
  • The competent authorities in the event of a legal obligation (TRACFIN, tax authorities, judicial authorities)

JOHYA does not transfer or sell personal data to third parties for commercial purposes.

6. Transfers outside the European Union

Certain providers (notably Shopify) may process data outside the European Union. These transfers are governed by appropriate safeguards in accordance with Articles 44 et seq. of the GDPR (standard contractual clauses, adequacy decisions).

7. Retention period

Data is retained for the following periods:

  • Order and invoicing data: 10 years from the close of the financial year (accounting obligation)
  • Inactive customer account data: 3 years from the last contact
  • AML/CFT data: 5 years from the end of the business relationship
  • Cookies: variable duration, see the Cookie policy
  • Prospecting data: 3 years from the last contact with the prospect

8. Rights of data subjects

In accordance with Articles 15 to 22 of the GDPR, the Client has the following rights:

  • Right of access to their data
  • Right to rectification
  • Right to erasure ("right to be forgotten"), within the limits of legal retention obligations
  • Right to restriction of processing
  • Right to portability
  • Right to object, in particular to commercial canvassing
  • Right to withdraw consent at any time where the processing rests on it
  • Right to give directions on the fate of their data after their death

These rights may be exercised by sending an email to administratif@johya.com, together with a copy of an identity document if there is any doubt as to the identity of the applicant.

The Client also has the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or via the website www.cnil.fr

9. Security

JOHYA implements the appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, accidental loss, alteration, unauthorized disclosure or access.