Site de démonstration commandes indisponibles

Draft — pending review by legal counsel

This text is a reference template drafted from public sources (CNIL guidance, French Consumer Code, LCEN Act, GDPR). It must be reviewed, completed and validated by a lawyer or in-house legal team before going live. OptoCenter accepts no liability for use of this text as-is.

Privacy policy

Last updated: to be completed

1. Data controller

The controller of personal data processing is OptoCenter, whose details appear in the legal notice. Contact for any question relating to personal data: dpo@optocenter.fr.

2. Data collected

OptoCenter collects the following categories of data:

  • Account data: first name, last name, e-mail, password (hashed), phone, shipping and billing addresses.
  • Order data: order history, invoices, payment methods used (without retention of card numbers — Stripe is the provider).
  • Optical prescription (Rx) data: uploaded prescription, correction values. Health data within the meaning of article 9 GDPR — legal basis: performance of the contract for the supply of corrective optics.
  • Browsing data: technical session cookie, server logs (IP, user-agent) for security purposes.

3. Purposes and legal bases

Your data is processed in order to:

  • Fulfil your order and deliver it — legal basis: performance of the contract (art. 6.1.b GDPR)
  • Manage your customer account — performance of the contract
  • Process your optical prescription — performance of the contract + explicit consent (art. 9.2.a GDPR)
  • Issue invoices and retain accounting records — legal obligation (art. 6.1.c GDPR; L.123-22 French Commercial Code)
  • Ensure site security and prevent fraud — legitimate interest (art. 6.1.f GDPR)
  • Send you transactional e-mails (confirmation, delivery, review request) — performance of the contract / legitimate interest

4. Recipients

Your data is accessible to authorised OptoCenter internal services and, where applicable, to the following processors:

  • Stripe — payment provider (Ireland, PCI-DSS compliance)
  • [Hosting provider] — technical site hosting
  • [Carrier — Chronopost / Colissimo / Mondial Relay] — physical delivery
  • [Transactional e-mail service — e.g. Mailgun, SendGrid, Amazon SES] — notification delivery

No data is transferred or sold to third parties for commercial purposes.

5. Retention periods

  • Customer account: 3 years from last activity (CNIL recommendation)
  • Invoices and accounting records: 10 years (article L.123-22 of the French Commercial Code)
  • Optical prescriptions: 3 years (CNIL recommendation on opticians)
  • Connection logs: 12 months (article L.34-1 CPCE)
  • Payment data: not retained by OptoCenter — see Stripe's policy

6. Security

OptoCenter implements appropriate technical and organisational measures to ensure a level of security adapted to the risk: TLS encryption of all communications, hashed passwords (BCrypt), role-based admin access partitioning, sensitive-action audit logging, regular encrypted backups.

7. Your rights

In accordance with articles 15 to 22 of the GDPR, you have the following rights:

  • Right of access to your data
  • Right of rectification of inaccurate data
  • Right to erasure (« right to be forgotten »)
  • Right to restriction of processing
  • Right to data portability (CSV / JSON format)
  • Right to object to processing
  • Right to withdraw consent at any time, without retroactive effect
  • Right to set directives on the fate of your data after death

To exercise these rights: dpo@optocenter.fr (attach a copy of identity document). Response time: 1 month maximum.

In the event of an unsatisfactory response, you may lodge a complaint with the CNIL: www.cnil.fr/en/plaints.

8. Cookies

Cookie usage is detailed in the cookie policy.