Privacy Policy
GRIS CIEL STUDIO is committed to protecting your privacy. This Privacy Policy explains how personal data is collected, used, disclosed, and safeguarded when you visit this website or use its services. The site operates as an online business based in France and complies with the General Data Protection Regulation (GDPR), the French Data Protection Act (Loi n° 78-17), and other applicable laws.
1. Data Controller
The data controller is GRIS CIEL STUDIO, France. For all data protection matters, please contact us exclusively through the PGP-encrypted contact form on the Contact page.
2. Personal Data Collected
Only the personal data strictly necessary for the purposes described below is collected (data minimization principle). This may include:
- Contact information (name, email address) when you use the contact form or subscribe to updates (with consent).
- Order information (name, email, shipping address, order details) when you place a purchase.
- Contact email provided when submitting a purchase request (request-to-buy), used to confirm your request, send your payment link, and notify you of its status.
- Technical and usage data (IP address, browser type, pages visited, device information) for security, site operation, and analytics limited to what is essential.
- Payment information: handled directly by the payment processor (Stripe). Full card details are not stored on this site.
3. Purposes and Legal Bases for Processing
Personal data is processed for the following purposes on the following legal bases:
- Providing e-commerce services and fulfilling orders (performance of contract).
- Processing purchase requests, including review, approval or decline, and managing the payment link (performance of contract).
- Sending transactional communications about your requests and orders, such as confirmations, payment links, and status updates (legitimate interest).
- Responding to inquiries and customer support (legitimate interest or consent).
- Complying with legal and tax obligations (legal obligation).
- Improving and securing the website (legitimate interest).
- Marketing communications, only with your prior consent (consent; easily withdrawable at any time).
4. Recipients and Data Sharing
Your personal data may be shared with trusted service providers acting as processors, including:
- Payment processing: Stripe (compliant with PCI-DSS).
- Hosting, CDN, and security: Cloudflare.
- Transactional email delivery: Resend (used to send request, order, and payment notifications).
- Email / communication infrastructure as needed for encrypted delivery of contact messages.
Personal data is not sold. Data is only shared when necessary to provide the service, to comply with law, or to protect rights.
5. International Data Transfers
Some service providers (such as Stripe and Cloudflare) may process data in countries outside the European Economic Area, including the United States. Where such transfers occur, appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission or other valid transfer mechanisms.
6. Data Retention
Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal obligations (e.g., accounting and tax records typically 5–10 years in France), or to resolve disputes. Purchase requests are retained for the duration of the transaction and, where applicable, for the legal retention periods required for accounting and tax purposes. Declined or expired requests are automatically purged 90 days after they are closed. When data is no longer needed, it is securely deleted or anonymized.
7. Your Rights
Under the GDPR and French law, you have the following rights regarding your personal data (subject to legal exceptions):
- Right of access and to obtain a copy of your data.
- Right to rectification of inaccurate data.
- Right to erasure ("right to be forgotten").
- Right to restriction of processing.
- Right to data portability.
- Right to object to processing (including direct marketing).
- Right to withdraw consent at any time (without affecting prior processing).
- Right to lodge a complaint with the French data protection authority (CNIL) or your local supervisory authority.
To exercise any of these rights, please use the encrypted contact form. Information may be requested to verify your identity before responding.
8. Cookies and Tracking Technologies
Only strictly necessary cookies and similar technologies are used, required for the basic functioning of the website (e.g., session management, cart functionality, and security). No third-party advertising or unnecessary analytics cookies that require prior consent under ePrivacy rules are used.
You can control or delete cookies through your browser settings. Disabling certain cookies may affect site functionality.
9. Security
Appropriate technical and organizational measures are implemented to protect personal data against unauthorized access, alteration, disclosure, or destruction. Contact form submissions are encrypted end-to-end using PGP before transmission. Payment processing is handled by Stripe using industry-standard security.
Request contact emails are stored in Cloudflare R2 storage. Data is encrypted at rest by Cloudflare and transmitted over TLS in transit. Access to request records is restricted to token-protected endpoints and is not exposed through public listings. No payment card data is stored; payment details are processed solely by Stripe.
10. Changes to This Policy
This Privacy Policy may be updated from time to time to reflect changes in practices or legal requirements. The "last updated" date at the bottom will indicate the effective version. Material changes will be communicated via the website or contact channels.
11. Contact
For any questions about this Privacy Policy or to exercise your rights, please use the secure PGP contact form available on the Contact page. This ensures end-to-end encryption of your inquiry.
Last updated: August 2026