Confidentiality Policy

Maison Alsacienne de Biscuiterie, MAB-ATELIER – SAS grants great importance to the privacy of internet users, and undertakes to protect their personal data, in compliance with the applicable French and European legislation. Visitors are not required to enter any personal data in order to view the Website www.maison-alsacienne-biscuiterie.com (hereinafter referred to as the "Website").

This Confidentiality Policy, hereinafter referred to as the "Policy", outlines our practices in relation to the information that we collect through our Website and the uses we make of it.

1. Data Controller identity

The company Maison Alsacienne de Biscuiterie, MAB-ATELIER - SAS, as identified above, acts within its capacity as Data Controller in relation to the personal data collected on the Website, in its French version:

  • Company MAB-ATELIER - SAS
  • Siret: 803 762 129 00015
  • Address: 7 rue Emile Schwoerer ZI Nord 68000 COLMAR (FR)

2. Scope and acceptance of this Policy

This Policy applies solely to the information connected via the Website and does not apply to any information collected from other source, particularly though not exhaustively, Facebook®, Twitter®, YouTube® or any other third-party network or website.

By using this/these Website/s, you hereby accept the terms and conditions of this Policy Should you reject the terms and conditions of this Policy, we invite you not to use the Website and to refrain from sending us any personal information.

2.1 Registration and authentication - Facebook Oauth

The registration or authentication of the User authorizes the Website to identify him and gives him access to dedicated services. As described below, third parties may provide registration and authentication services. In this case, the Site may access Data stored by these third parties for registration or identification purposes.

  • Facebook Oauth

Facebook Oauth is a registration and authentication service provided by Meta Platforms, Inc. or Meta Platforms Ireland Limited, depending on how the Owner manages the processing of Data, which is connected to the Facebook social network.

3. Data collected on our Website

3.1 What data is collected?

In particular, we collect and process your name, address, email address, password, phone number, IP address, login data and browsing data.

The obligatory or optional nature of the data is indicated by an asterisk (*) at the entry points from which we collect the data. Some data is collected automatically through your actions on our website.

We also take audience measurements. For example, we measure the number of pages viewed, number of website visits, and the activity of website visitors and their return frequency.

3.2 When do we collect data?

We collect the information that you provide when:

  • You create your "My Account" customer account
  • You place an order on our website
  • You're browsing our website and viewing products
  • You take part in a competition or giveaway
  • You contact our Customer Services
  • You leave a review
  • You subscribe to our newsletter
  • You give your opinion via the Verified Opinion solution
  • You accept cookies through the Axeptio solution

3.3 Purposes of collection personal data

Each form featured on the website is limited to the collection of only strictly necessary personal data, and systematically indicates: The purposes for the personal data collection, and the obligatory or optional nature of the data.

Under no circumstances may Maison Alsacienne de Biscuiterie, MAB-ATELIER - SAS use this personal data for a purpose other than that explicitly identified on the form and hence accepted by the internet user. In the same sense, this personal data may not be sent or sold to third parties without explicit indication of this possibility in the form.

Hence, the legal basis for the collection and processing of the Personal Data is the specific, clear and informed consent of the internet user. The Personal Data is collected and processed for the fulfilment of the following purposes:

  • Creation of a Customer Account
  • Order processing and delivery
  • Newsletter sign-up
  • Competition and giveaway organisation and management
  • Contact and support
  • Commercial prospecting
  • Commercial relations management.

3.4 Recipient of the Personal Data

The personal data collected on our Website is destined solely for Maison Alsacienne de Biscuiterie, MAB-ATELIER - SAS.

It may also be sent to sub-contractor companies which Maison Alsacienne de Biscuiterie, MAB-ATELIER - SAS uses the services of, for the fulfilment of services and orders, namely management, fulfilment, processing and payment :

  • Sendinblue
  • Shopymind
  • Net Reviews
  • La Poste
  • Ukoo
  • Axeptio
  • CM-CIC
  • Trustteam
  • Verifone
  • PayPal

If necessary, your Personal Data may be sent to our commercial partners for their own activity, in compliance with the applicable legal bases.

The sub-contractors and commercial partners to which your Personal Data may be sent present sufficient guarantees in regard to the implementation of the appropriate technical and organisational measures in order to ensure the security and confidentiality of your Personal Data.

Lastly, Maison Alsacienne de Biscuiterie, MAB-ATELIER - SAS may need to disclose Personal Data to the judicial authorities or to any other authority when required by law.

3.5 Data transfer outside of the EU

You are hereby informed that your data may be sent by Maison Alsacienne de Biscuiterie, MAB-ATELIER – SAS, for the requirements of the purposes set out in these terms and conditions, to companies based in countries outside of the European Union which do not present an adequate level of protection in regard to personal data protection. Prior to transfer outside of the European Union, Maison Alsacienne de Biscuiterie, MAB-ATELIER – SAS shall implement all procedures required to obtain the necessary guarantees in regard to the security of such transfers. In this regard, Maison Alsacienne de Biscuiterie, MAB-ATELIER – SAS undertakes to ensure that the said transfer is covered by the Privacy Shield data protection measure implemented between the European Union and the United States or by the signing of standard contractual clauses drawn up by the European Commission, or by the implementation of binding corporate rules ("BCR").

3.6 Term of storage

Maison Alsacienne de Biscuiterie, MAB-ATELIER - SAS shall store your Personal Data for the necessary term, or for the term required by the applicable law.

4. Your rights

By sending a written request, internet users can access their Personal Data, ask for it to be modified or rectified, or to request that it is removed from the database held by Maison Alsacienne de Biscuiterie, MAB-ATELIER – SAS.

In regard to the right to access, and in compliance with Article 15 of the GDPR, the internet user has the right to consult Maison Alsacienne de Biscuiterie, MAB-ATELIER – SAS with a view to obtaining (i) the communication of their Personal Data in an accessible format, (ii) the confirmation that their Personal Data is subject, or not, to processing, (iii) the communication of the purposes of such processing, the categories of Personal Data processed and any parties to whom their Personal Data is communicated, and (iv) the term of retention for their Personal Data or the criteria used to determine this term.

In compliance with Article 16 of the GDPR, the right to rectify grants internet users the right to ask Maison Alsacienne de Biscuiterie, MAB-ATELIER – SAS to rectify, supplement or update their Personal Data when it is inaccurate, incomplete, ambiguous or expired.

Under the conditions provided for by Article 17 of the GDPR, internet users have the right to delete their Personal Data, entitling them to request that Maison Alsacienne de Biscuiterie, MAB-ATELIER – SAS deletes their Personal Data as soon as possible, particularly when it is no longer necessary for the purposes for which it was collected.

Internet users also have the right to limitation in regard to the processing of the Personal Data cited in the scenarios listed in Article 18 of the GDPR. They can hence request that their personal data is retained solely for purposes of:

  • Verifying the accuracy of the Personal Data contested,
  • Use as part of the dispute, application or defence of their rights in legal proceedings, and despite Maison Alsacienne de Biscuiterie, MAB-ATELIER – SAS no longer having any use for it,
  • Verifying whether the legitimate grounds of Maison Alsacienne de Biscuiterie, MAB-ATELIER – SAS take precedence over their own in the scenario whereby they should oppose the processing based on the legitimate interest of Maison Alsacienne de Biscuiterie, MAB-ATELIER – SAS,
  • Satisfying their request for the limitation of the use of their data - rather than a deletion - in the scenario whereby the data is processed illicitly.

Under the circumstances provided for by Article 20 of the GDPR, internet users have the right to portability for their Personal Data, entitling them to recovering from Maison Alsacienne de Biscuiterie, MAB-ATELIER – SAS the Personal Data that they have provided, in a structured format which is commonly used and computer-readable, for the purposes of sending this Data to another Data Controller.

In compliance with Article 21 of the GDPR, internet users have the right to oppose, at any time, the processing of their Personal Data for the purposes of commercial prospecting.

To exercise their aforementioned rights to access, rectify, delete, limitation, portability and opposition, internet users must send their request via email to the following address: service-client@mabiscuiterie.com.

In the event of a breach of their Personal Data which may pose a risk to their rights and freedoms, Maison Alsacienne de Biscuiterie, MAB-ATELIER – SAS shall report this breach to the CNIL (French Data Protection Authority) as soon as possible. Maison Alsacienne de Biscuiterie, MAB-ATELIER – SAS shall also inform internet users, as soon as possible and in compliance with the provisions of Article 34 of the GDPR.

Without prejudice to any other administration or judicial recourse, internet users who believe that the processing of their Personal Data constitutes a breach of the provisions set out by the applicable legislation may file a claim with a competent authority, such as the French Data Protection Authority (CNIL).

The security article should not be included in the Confidentiality Policy, but rather in the T&Cs of Use.

5. Security

The security of your Personal Data is of the utmost importance to us. The personal data collected on the website www.maison-alsacienne-biscuiterie.com is processed in line with secure protocols which considerably limit the risks of interception or retrieval by third parties. Nevertheless, given the open nature of the internet, we cannot entirely rule out the risk of hacking or unauthorised access by third parties. By continuing to use our Website, you accept these risks. Insofar as the applicable laws allow, we will not accept any liability in the event of direct or indirect damage, losses, costs incurred, whether these be contractual, tortuous or entailed by negligence, that you may suffer in the event of the unauthorised access, loss or alternation of your personal data.