PRIVACY POLICY

1. Data Controller and point of contact

Éclairage Français (hereinafter "the Site") is operated by the company L&L4S, a simplified joint-stock company with a sole shareholder (SASU) registered with the Paris Trade and Companies Register under number 941 794 141, whose registered office is located at 9 rue des Colonnes, 75002 Paris, France (hereinafter "we" or "L&L4S").

This policy describes, in accordance with Articles 12 to 14 of Regulation (EU) 2016/679 ("GDPR") and Act No. 78-17 of January 6, 1978 as amended ("LIL"), how we collect, use, store, and secure your personal data when you use the Site or our online lighting sales services.

The data controller is L&L4S, a simplified joint-stock company with a sole shareholder registered with the Paris Trade and Companies Register under number 941 794 141, whose registered office is located at 9 rue des Colonnes, 75002 Paris, France.
For any questions regarding personal data protection, you may write to: support@eclairagefrancais.fr.

To date, L&L4S does not meet the criteria requiring the mandatory appointment of a Data Protection Officer ("DPO") within the meaning of Article 37 of the GDPR. Any questions regarding this policy may, however, be addressed to the address above.

2. ORIGIN AND CATEGORIES OF DATA PROCESSED

2.1 Data you provide directly

Identity: last name, first name, title, company, SIREN/SIRET number, intra-community VAT number (business clients)
Contact details: postal address, email, phone number
Account: username, hashed password (BCrypt)
Transactions: shopping cart, order history, Stripe token, last 4 digits of the card, expiration date
Communications: forms, emails, chat, customer service
Marketing preferences: subscriptions, consents, customer categories

Fields marked with an asterisk (*) in our forms are mandatory; otherwise, we may be unable to process your request or order.

2.2 Data collected automatically

Connection: IP address, session ID, timestamp (logs stored for 12 months)
Navigation: pages visited, products viewed, browser language, operating system, device type
Trackers (cookies): see section 9

2.3 Data from third parties

Stripe: authorization status, risk indicator, card issuing country — retained for 24 months unless there is a dispute
Colissimo: tracking number, shipping status, selected pickup point

We do not collect any special categories of data (GDPR arts. 9 & 10).

3. Purposes and legal bases for processing

Order processing, delivery and invoicing

Legal basis: performance of a contract.

Customer account creation and management

Legal basis: performance of a contract.

Customer service management and requests via the contact form

Legal basis: legitimate interest (ensuring service continuity and customer satisfaction).

Sending newsletters and promotional offers

Legal basis: consent.

Non-intrusive marketing segmentation (active/inactive customers, professionals/individuals)

Legal basis: legitimate interest (offering relevant promotions to grow the business).

Audience measurement and analytics

Legal basis: consent (acceptance of cookies).

Fraud prevention and Site security (connection logs, captcha, IP filtering)

Legal basis: legitimate interest (guaranteeing the security of transactions and the Site).

Retention of invoices and accounting documents

Legal basis: legal obligation (Article L123-22 of the French Commercial Code).

When processing is based on our legitimate interest, L&L4S has conducted a “balancing test” to ensure that your fundamental rights and freedoms are not disregarded. You may object to these processing activities at any time (see section 10).

4. Data retention periods

– Data relating to an inactive customer account (no login or purchase) is kept for three years from the date of the last activity, in accordance with CNIL recommendation no. 2023-01 on "prospecting".

– Information related to orders and billing is archived for ten years, in application of Article L123-22 of the French Commercial Code.

After-sales service (SAV) and support records are kept for five years after they are closed, a duration corresponding to the applicable contractual limitation period.

Non-essential cookies (audience measurement, personalization) expire no later than thirteen months after they are deposited, in accordance with the CNIL "cookies" recommendation.

– Data intended for marketing (newsletter and prospecting) is kept until consent is withdrawn, or failing that, for three years after the last contact from the prospect, in accordance with CNIL deliberation 2019-093.

– Any copy of an identity document provided for the exercise of a GDPR right is kept for one year – or three years in the case of an objection – as provided for by Article 9 of Decree 2007-451.

Beyond these periods, the data is either deleted or rendered permanently anonymous for statistical purposes.

5. Data recipients

5.1 Internal access (authorized personnel)

- Logistics
- Customer service
- Marketing
- Finance Department
- IT Department

5.2 Sub-processors (Art. 28 GDPR contracts signed)

Shopify Inc. – e-commerce hosting; data stored in Canada (a country benefiting from an adequacy decision) and then, where applicable, transferred to the United States under standard contractual clauses (SCC 2021/914).

Stripe Payments Europe Ltd – payment processing; processing and storage in Ireland (European Economic Area).

Stripe Inc. – technical support; potential transfers to the United States governed by SCCs and reinforced by encryption measures.

La Poste / Colissimo – logistics and delivery; processing exclusively in France.

Klaviyo Inc. – e-mailing platform; processing in the United States under SCC 2021/914, with data pseudonymization.

Google LLC (Google Analytics 4 via Frankfurt proxy) – audience measurement; collection via a European proxy, transfers to the United States governed by SCCs and encryption of identifiers.

5.3 Legally authorized third parties

Judicial, administrative or tax authorities, statutory auditors, lawyers.
No data is sold or rented.

6. Transfers outside the European Economic Area (EEA)

Row content

7. Security measures (Art. 32 GDPR)

Shopify Infrastructure: SOC 2 Type II, ISO 27001, PCI-DSS Level 1
Encryption: HTTPS/TLS ≥ 1.2 on 100% of pages
Backups & DRP/BCP: quarterly restoration tests, AES-256 encryption
Administrator accounts: strong passwords + MFA
Principle of least privilege: authorization matrix reviewed semi-annually
Payment data: tokenized & encrypted by Stripe (PCI-DSS Level 1)

The measures are re-evaluated annually or after any major change.

8. Protection of minors

Our products and services are not intended for persons under 18 years of age. We do not knowingly collect data relating to minors. Minors must obtain the authorization of their legal guardian to use the Site.

9. Cookies and trackers

A consent management platform ("CMP") banner is displayed during your first visit. You can change your choices at any time via the "Manage cookies" link at the bottom of the page.

The durations indicated below correspond to the maximum time each cookie can remain active; you can delete these cookies at any time via your browser.

The cookies placed on the Site fall into three categories:

  1. essential for the operation of the Site (shopping cart management, language memorization, authentication). They are based on L&L4S's legitimate interest and expire no later than twelve (12) months after they are placed.
  2. used to produce anonymous traffic statistics and improve usability. They are only placed with your consent and have a maximum lifespan of thirteen (13) months.
  3. allow for content personalization and abandoned cart follow-ups. Their placement requires your consent; their retention period does not exceed thirteen (13) months.

You can access your choice settings at any time from the "Cookie management" banner.

10. Your rights (Art. 15 to 22 GDPR)

You have the following rights:

  1. Access to your data;
  2. Rectification of inaccurate data;
  3. Erasure ("right to be forgotten"), where applicable;
  4. Restriction of processing;
  5. Objection to processing based on legitimate interest or for direct marketing purposes;
  6. Portability of data provided on the basis of consent or contract;
  7. Withdrawal of consent at any time for processing based thereon;
  8. Post-mortem directives regarding the fate of your data after your death.

You may exercise these rights free of charge by writing to support@eclairagefrancais.fr and attaching proof of identity if necessary. We will respond within a maximum period of one month, which may be extended by two months for complex requests (Art. 12 §3 GDPR).

If, after contacting us, you believe that your rights are not being respected, you may file a complaint with the French supervisory authority (CNIL): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 – www.cnil.fr.

11. Automated decision-making and profiling

No decision producing legal effects concerning you is based exclusively on automated processing. Marketing segmentations are based on non-intrusive profiling to which you may object at any time.

12. Social media

We operate official pages on Instagram, Facebook, and YouTube. Your interactions with these platforms are governed by their own privacy policies.

For any questions regarding this policy, you may contact us:
via the contact form
by email at: support@eclairagefrancais.fr;
by mail at the following address:
L&L4S – 9 rue des Colonnes, 75002 Paris, France

Consulting & serviceMonday to Friday, 9am–7pm
Secure PaymentSSL-encrypted transactions
Returns & exchangesVia our returns portal

Back to top