Privacy Policy
NMR GEMS PRIVACY POLICY
Document updated on 12/27/2022
NMR GEMS (“ NMR GEMS ”, “ our ”, “ we ” and “ us ”) and our partners respect your privacy.
We ask that you read this privacy policy carefully to understand how your personal data is collected, processed and stored when you use this NMR GEMS website, accessible via the url www.naomierichard.com.
All personal data collected on this website are processed under the responsibility of the company NMR GEMS , SASU with share capital of €1,000, registered in the Paris Trade and Companies Register under number 909821902, and having its registered office at 91 Rue du Faubourg Saint-Honoré, 75008 Paris, France.
Within the meaning of the regulations applicable to personal data, NMR GEMS is therefore responsible for processing.
This Privacy Policy describes:
- How NMR GEMS uses your personal data
- How NMR GEMS shares your personal data
- How NMR GEMS protects your personal data
- Where NMR GEMS hosts and transfers your personal data
- How you can exercise your rights relating to your personal data
- Privacy Policy Updates
- How to contact us
__________
- How NMR GEMS uses your personal data
NMR GEMS may use your personal data for the following purposes:
- Create your customer account on this website
- Manage orders for products and/or services
- Publish and manage your reviews and/or comments left on the website
- Send you our newsletter, if you have subscribed to it
- Respond to your contact request made from our website
The data collected is necessary for the execution of the contract entered into with NMR GEMS when you use our website to order the products and/or services available for sale on the site.
The processing of your personal data in order to send you our newsletter is, however, based solely on your consent to receive our newsletter, which you can withdraw at any time. If you do not consent to the sending of the newsletter, please note that this will not prevent you from creating your customer account and placing orders on our website.
- How NMR GEMS shares your personal data
Within NMR GEMS, and with regard to each processing purpose, personal data concerning you is collected, processed and stored by authorized NMR GEMS personnel, only within the framework of their respective skills, and in particular by the customer service, the marketing department and the IT department.
We do not share personal data with other companies, organizations and individuals, unless one of the following circumstances applies:
(1) Sharing with prior consent : After obtaining your consent, NMR GEMS will share the information you have authorized with the specific third parties or categories of third parties indicated when collecting your consent.
(2) Sharing with our service providers : NMR GEMS may also disclose your information to companies that provide services to us or on our behalf. These service providers include companies that provide IT services such as our hosting or email delivery service, product delivery services, or that provide marketing activities on our behalf. These service providers may use your information only for the purpose of providing services to you on behalf of NMR GEMS.
(3) In execution of a legal obligation, sharing in accordance with laws and regulations : NMR GEMS, may share your information as stipulated by laws and regulations, in order to resolve legal disputes, or as stipulated by judicial or administrative authorities under the law.
NMR GEMS will ensure the legality of any sharing of personal data through data processing clauses with the companies with whom your personal data is shared, requiring them to comply with this privacy policy and to take appropriate security and confidentiality measures when processing personal data.
III. How NMR GEMS protects your personal data
NMR GEMS takes the security of your personal information very seriously and has adopted industry standard practices to protect your personal information and prevent unauthorized access, disclosure, use, modification, damage or loss of such information.
We have also taken the necessary precautions to preserve, through our host, the security and confidentiality of the data, and in particular to prevent them from being distorted, damaged or communicated to unauthorized persons.
NMR GEMS also adopts the following organizational measures:
(1) We adopt reasonable and feasible measures to ensure that the personal data collected is minimal and relevant to what is necessary, having regard to the purposes for which it is processed.
(2) We retain your personal data for the period that is strictly necessary in relation to the purpose of the processing, unless the retention of your data is required or permitted by law. For example, we retain data relating to the execution of your orders for the period required by law for the purpose of retaining accounting records, i.e. a maximum of 10 years from the financial year concerned.
(3) We deploy access control mechanisms to ensure that only authorized personnel can access your personal data.
In the event of a personal data breach, NMR GEMS will comply with applicable legal and regulatory requirements for notification of personal data breaches to the relevant supervisory authorities and/or data subjects.
- Where NMR GEMS hosts and transfers your personal data
Your personal data will be hosted within the hosting infrastructure of our host, Shopify, located in the USA.
- How you can manage your rights regarding your personal data
You have the right to access, rectify, erase, limit and oppose the processing of your personal data, as well as the right to define guidelines regarding the fate of your data after your death and the right to the portability of your personal data.
The CNIL defines personal data as “any information relating to an identified or identifiable natural person. But because they concern people, they must retain control over them”.
The Regulation of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data corresponds to the general regulation on the protection of personal data and sets out the right of appeal of the individual before the CNIL.
You can contact us at any time at the addresses indicated in the section "How to contact us" below in order to exercise your rights regarding personal data under the conditions set by the applicable regulations. You must indicate which right you intend to exercise as well as all the details necessary for us to respond to your request.
These rights are exercised under the conditions set out by the applicable regulations.
- The right of access means that you can ask us at any time to inform you whether we are processing personal data concerning you and, if so, to inform you which personal data are concerned as well as the characteristics of the processing carried out.
- The right to rectification means that you can ask us to rectify your personal data when it is inaccurate. You can also ask for your personal data, if incomplete, to be completed to the extent that this is relevant to the purpose of the processing in question.
- The right to erasure means that you can request to erase your personal data in particular when:
- Their conservation is no longer necessary with regard to the purposes for which they were collected;
- Your personal data is processed on the basis of your consent, you wish to withdraw this consent, and there is no other legal basis that could justify the processing;
- You have objected to the processing of your personal data and therefore wish for it to be deleted;
- Your personal data has been unlawfully processed;
- Your personal data must be erased to comply with a legal obligation provided for either by European Union law or by French law.
- The right to restriction means that you can ask us to restrict the processing of your personal data:
- When you contest the accuracy of your personal data for a period enabling us to verify its accuracy;
- When, following processing established as non-compliant, you prefer the limitation of processing to the complete erasure of your personal data;
- When we no longer need your personal data for the purposes of the processing but you still need them for the establishment, exercise or defense of legal claims;
- When you have objected to the processing of your personal data and you wish to limit the processing for the period allowing us to verify whether the legitimate reason you invoke is justified.
Restriction of processing means that the processing of your personal data will then be limited to the storage of your corresponding personal data. We will then no longer carry out any further operations on the personal data in question.
- The right to object means that you can object to the processing of your personal data, when this processing is based on the pursuit of the legitimate interest of NMR GEMS. The right to object is exercised subject to justifying a legitimate reason relating to your particular situation. We will then cease the processing in question unless there are legitimate and compelling reasons justifying the continuation in accordance with the applicable regulations.
- The right to define instructions regarding the fate of your data after your death allows you to make known your instructions regarding the retention, deletion and communication of your personal data after your death.
- The right to portability means that you can ask us, under the conditions set by the applicable regulations, to receive your personal data in a structured, commonly used and machine-readable format, and to transmit them to you, or to ask us to transmit them directly to a third party of your choice when this is legally and technically possible.
When we process your personal data on the basis of your consent, you finally have the option to withdraw your consent at any time by contacting the addresses indicated in the section "How to contact us" or by clicking on the unsubscribe link present in each of our communications.
However, the withdrawal of your consent does not affect the validity of the processing carried out before this withdrawal.
- Updates to this Privacy Policy
NMR GEMS reserves the right at any time to modify or update, in whole or in part, this privacy policy, due to the modification of the applicable regulations regarding the protection of personal data or the data processing carried out.
Any substantial changes to the privacy policy will be notified to you by email when you have provided us with a valid email address and will be published on the website. We recommend that you regularly review this privacy policy in order to have a full understanding of our commitments regarding the security and protection of your personal data.
-
VII. How to contact us
If you have any questions, comments or suggestions, please contact us by visiting the contact us page or submitting them to contact@naomierichard.com .
Or by post to 91 Rue du Faubourg Saint-Honoré, 75008 Paris, France.
If you are not satisfied with the response provided by NMR GEMS to a request to exercise rights in accordance with Article V above or if you wish to report a breach of applicable data protection regulations, you have the right to lodge a complaint with the CNIL by post (CNIL - 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07) or on its website (www.cnil.fr), or with the data protection authority of the country in which you usually reside or work.