Privacy policy
Privacy and Cookie Policy
1. Privacy Policy
Atelier Benneton (hereinafter “Atelier Benneton”) is committed to ensuring that all personal data processing carried out in connection with its activities complies with European Regulation (EU) 2016/679, known as the General Data Protection Regulation (“GDPR”), and with the French Data Protection Act.
This Privacy Policy (the “Policy”) explains how and why we use your personal data, the rights available to you and how you may exercise them.
1. What is personal data?
Personal data (“Personal Data” or “Data”) means any information relating to an identified or identifiable natural person, whether directly or indirectly, including by reference to an identifier such as:
- A surname, first name or email address;
- An online identifier or IP address;
- Location data or any other information that may be used to identify you.
2. Who does this Privacy Policy apply to?
This Policy applies to all our online services and our interactions with third parties.
It is intended to inform:
- Users of the Website;
- Prospective customers;
- Customers;
- Suppliers and partners;
- Job applicants.
3. Who collects your Data?
The data controller within the meaning of the GDPR is:
Atelier Benneton SAS
75 boulevard Malesherbes
75008 Paris, France
Telephone: +33 (0)1 43 87 57 39
Email: atelier@bennetongraveur.com
4. How do we collect your Data?
Data relating to Website users
Data is collected through:
- Online contact forms;
- Your use of and browsing on the Website, particularly through the use of cookies.
Data relating to prospective customers and customers
Data is collected:
- When you request information, quotations or commercial proposals;
- In connection with the conclusion and performance of contracts;
- Through commercial communications by email, telephone or online forms.
5. Why do we collect your Data?
Data relating to Website users
| Purpose | Categories of Data | Legal basis |
| Handling enquiries submitted through forms and managing online sales | Identification and contact details, information relating to the enquiry | Legitimate interest |
| Audience measurement and statistics | Browsing data, including IP addresses and cookies | Consent |
| Cookie management | Browsing data | Consent |
For further information, please refer to our Cookie Policy.
Data relating to prospective customers
| Purpose | Categories of Data | Legal basis |
| B2B and B2C commercial prospecting | Identification and contact details, professional information and information relating to the enquiry | Legitimate interest |
| Sending information and offers | Contact details | Consent or legitimate interest* |
\*The applicable legal basis depends on whether the marketing communication is addressed to a business or an individual.
Data relating to customers and suppliers
| Purpose | Categories of Data | Legal basis |
| Contractual and commercial management | Identification and contact details, professional information and information relating to the enquiry | Performance of a contract |
| Administrative, accounting and tax management | Financial and invoicing data | Legal obligation |
| Satisfaction surveys and studies | Contact details | Legitimate interest |
| Recording of Google Meet videoconferences | Contact details, image, voice and content of discussions | Consent |
6. Are you required to provide your Personal Data?
Certain Data is required for us to manage our services and contractual relationships.
Mandatory fields are marked with an asterisk (“*”).
Where such Data is not provided, we may be unable to process certain requests.
7. How long do we retain your Data?
We retain your Personal Data only for as long as is strictly necessary to fulfil the purposes for which it was collected and processed.
Where applicable regulations impose a specific retention period, particularly for accounting, tax, employment or commercial purposes, your Data will be retained for the minimum period required under the applicable local legislation.
At the end of the applicable retention periods, the Data will be:
- Deleted;
- Irreversibly anonymised; or
- Securely archived where necessary for the establishment, exercise or defence of legal claims.
Indicative retention periods:
| Categories of data subjects or Data | Retention period |
| Website users | Browsing Data is retained for a maximum of 13 months, in accordance with CNIL recommendations. Please refer to the Cookie Policy for further details. |
| Prospective customers | Data is retained for a maximum of three years from the date of the last contact. |
| Customers and suppliers | Data is retained for the duration of the contractual relationship and then archived for five years in accordance with applicable legal obligations. |
| Accounting and tax Data | Data is retained for ten years in accordance with applicable legal obligations. |
8. With whom do we share your Data?
Your Data may be disclosed to:
- Authorised internal departments, within the limits of their respective responsibilities;
- Subsidiaries and other entities of the Altavia Group, where necessary for the Group’s internal organisation, the sharing of certain services, including IT, support and administrative management, or the management of commercial relationships;
- Our technical service providers, including hosting, IT maintenance, CRM and IT support providers;
- Our professional advisers, including accountants, lawyers and statutory auditors;
- The Data Protection Officer (“DPO”), in connection with the monitoring, advisory and compliance duties set out in Article 39 of the GDPR;
- Administrative or judicial authorities where required by law or where we receive a legally valid request.
Depending on the circumstances, Group entities and our service providers act either as separate data controllers or as processors within the meaning of the GDPR.
Where they act as processors, they provide sufficient guarantees regarding the security, confidentiality and protection of Personal Data and are bound by contractual obligations that comply with Article 28 of the GDPR.
9. Is your Data transferred outside the European Union?
We are committed to limiting transfers of Personal Data outside the European Union as far as possible.
At present, your Data is primarily processed and hosted within the European Union. However, in certain strictly controlled circumstances, transfers of Data to countries outside the European Union may be necessary, particularly in connection with the use of certain tools, specific technical services or intra-group transfers.
Where such transfers take place, we ensure that they are subject to appropriate safeguards in accordance with Articles 44 et seq. of the GDPR. These safeguards may include appropriate contractual mechanisms, such as the Standard Contractual Clauses adopted by the European Commission, together with enhanced technical and organisational measures designed to provide a level of protection equivalent to that required within the European Union, including information-system security, access controls and encryption.
Any transfers of Data within the group to which we belong are also strictly regulated and carried out in compliance with the requirements of the GDPR, in order to ensure the confidentiality, integrity and security of your Personal Data.
10. What security measures have we implemented to protect you?
We are committed to implementing all technical and organisational measures necessary to protect your Personal Data, including impact assessments, audits, access-rights and authorisation-management policies, and application mapping.
In particular, we conduct audits of our service providers to ensure that appropriate security measures have been implemented to safeguard the integrity, confidentiality and availability of your Data.
Our agreements with service providers include specific provisions relating to Data protection and comply with applicable laws.
11. What are your rights?
In accordance with applicable regulations, you have the following rights:
- Right of access: to request a copy of the Data concerning you held by the Data Controller;
- Right to rectification: to correct or complete inaccurate Data concerning you;
- Right to erasure: to request the deletion of all or part of your Data;
- Right to object: to object to the processing of your Data, including profiling activities, where such processing is based on our legitimate interests. This right does not apply to processing that you have initiated yourself, such as a contact request or request for a quotation. In such cases, you may nevertheless exercise your right to erasure;
- Right to withdraw consent: to withdraw your consent at any time;
- Right to restriction of processing: to restrict the use of your Data while your request is being processed;
- Right to data portability: to request that certain Data processed by us be provided to you in a machine-readable format.
Where a Personal Data breach likely to result in a high risk to your rights and freedoms is identified, you will be informed of the breach as soon as reasonably possible.
You may also provide instructions concerning the retention, deletion and disclosure of your Personal Data after your death, in accordance with Article 85 of French Law No. 78-17 of 6 January 1978.
12. How can you exercise your rights?
You may exercise these rights and submit any related instructions by contacting us:
By post:
Marie Matuszczek – Managing Director
Atelier Benneton SAS
75 boulevard Malesherbes
75008 Paris, France
Or by email:
Depending on the nature of your request, and where there is reasonable doubt regarding your identity, we may ask you to provide proof of identity upon receipt of your request.
We will respond within one month of receiving your request. In certain circumstances, particularly due to the complexity of the request or the number of requests received, this period may be extended by a further two months.
You also have the right to lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (“CNIL”), the French supervisory authority responsible for the protection of Personal Data:
Commission Nationale de l’Informatique et des Libertés (CNIL)
3 Place de Fontenoy – TSA 80715
75334 Paris Cedex 07
France
Telephone: +33 (0)1 53 73 22 22
Website: www.cnil.fr
13. Amendments to this Privacy Policy
We may update this Policy by publishing a new version on our Website. Where this occurs, you will be informed the next time you visit the Website.
14. Contact
For any questions concerning this Privacy Policy, you may contact us:
By email: atelier@bennetongraveur.com
By post:
Marie Matuszczek – Managing Director
ATELIER BENNETON SAS
75 boulevard Malesherbes
75008 Paris, France
2. Cookie Policy
This Cookie Policy explains how and why Atelier Benneton SAS, hereinafter “Atelier Benneton SAS”, uses cookies and other tracking technologies when you visit its website, bennetongraveur.com, hereinafter the “Website”.
When you visit our Website, a “Cookie Management” module informs you that cookies may be used and allows you to accept or refuse each category of cookies individually.
When you accept or refuse the placement of cookies, your choice remains valid for six months, in accordance with the recommendations of the Commission Nationale de l’Informatique et des Libertés (“CNIL”).
At the end of this period, you will be asked again to provide or refuse your consent to the placement of these cookies.
1. What is a cookie?
A cookie is a small text file placed on your device, including a computer, smartphone or tablet, when you visit a website.
It enables the website to identify your browser during your visit and retain certain information about you.
2. Why do we use cookies?
We use cookies and other tracking technologies to:
- Facilitate and improve your use of our Website;
- Personalise the content and advertising displayed on our Website;
- Provide social-media features, including sharing buttons;
- Compile statistics concerning the use of and browsing on our Website.
3. List of cookies used
Necessary cookies
These cookies are required to ensure that the Website operates correctly and therefore do not require your consent.
| Cookie name | Provider | Purpose | Retention period |
| `_shopify_s` | Shopify | Maintains the browsing session, including the shopping basket and customer-account login. | 30 minutes |
| `_shopify_y` | Shopify | Visitor identifier used to manage the shopping basket and preferences. | 1 year |
| `cart` | Shopify | Stores the contents of the shopping basket. | 2 weeks |
| `secure_customer_sig` | Shopify | Enables secure customer-account authentication. | 20 years |
| `cookielawinfo-*` | Website | Records the visitor’s cookie-consent preferences. | 1 year |
Analytics cookies
These cookies allow us to measure Website traffic and usage. They are placed only with your consent.
| Cookie name | Provider | Purpose | Retention period |
| `_ga` | Distinguishes unique users through a randomly generated identifier for audience measurement purposes. | 2 years | |
| `_ga_*` | Stores the Google Analytics session status. | 2 years | |
| `_gid` | Stores a unique value for each page visited for audience-measurement purposes. | 1 day | |
| `_gat_UA-*` | Limits the volume of Data recorded on websites with high levels of traffic. | 1 minute |
Advertising cookies
These cookies are used to personalise advertising, measure campaign performance and display third-party content, including YouTube content and advertisements.
They are placed only with your consent.
| Cookie name | Provider | Purpose | Retention period |
| `_fbp` | Meta | Meta Pixel cookie used to identify browsers for conversion measurement and advertising targeting on Facebook and Instagram. | 3 months |
| `_fbc` | Meta | Meta Pixel cookie that records the advertisement click that led the visitor to the Website. | 3 months |
4. Consent management
Whether your consent is required depends on the type of cookie used.
We may place cookies that are strictly necessary to ensure the proper operation of the Website or to provide a service expressly requested by the user. Your consent is not required for these cookies.
Your consent is required for all other cookies, including advertising cookies and cookies used for sharing content on social media.
You may disable non-essential cookies through your browser settings or directly through our cookie-management tool.
You may accept or refuse cookies individually or refuse them systematically.
Please note that changing your cookie settings may affect your ability to access certain content and services that require the use of cookies.
Browser cookie-management links
Chrome: https://support.google.com/chrome/answer/95647
Firefox: https://support.mozilla.org/fr/kb/protection-renforcee-contre-pistage
Safari: https://support.apple.com/fr-fr/guide/safari/sfri11471/mac
Edge: https://support.microsoft.com/fr-fr/microsoft-edge
5. Data collected and transfers outside the European Union
Certain cookies provided by Google, YouTube or Microsoft may result in Data being transferred to the United States.
These services are governed by their own privacy policies:
Google: https://policies.google.com/privacy
Microsoft: https://privacy.microsoft.com/
6. Contact
For further information about how Atelier Benneton SAS processes your Personal Data and how to contact us, please refer to our Privacy Policy.