Privacy policy
Section 1 — Data Controller
DE KERCOET (DK) is the organisation responsible for the processing of personal data collected on the website www.dekercoet.com.
DE KERCOET (DK) — Limited Liability Company (SARL) with share capital of €199,970
Registered Office: 13 rue des Saints-Pères, 75006 Paris, France
RCS Paris: B 440 253 615
EU VAT number: FR 30 440 253 615
Email: bonjour@dekercoet.com — Telephone: +33 9 87 88 88 69
1.1 Data Protection Contact Point
DE KERCOET has not designated a separate Data Protection Officer (DPO). All data protection enquiries should be directed to the contact point: bonjour@dekercoet.com
Section 2 — Personal Data Collected
2.1 Categories of Personal Data Collected
DE KERCOET collects the following categories of personal data:
- Identification data: surname, first name, postal address, email address, telephone number
- Order data: product references, order history, bespoke furniture preferences and specifications
- Payment data: bank card numbers are processed by our payment provider (Stripe) and are not stored by DE KERCOET; bank details for transfers are retained solely for accounting purposes
- Browsing data: IP address, browser type, pages visited, visit duration (collected via Google Analytics)
- Communication data: content of exchanges by email, telephone, and contact forms
- Event data: professional contact details, business cards collected at trade shows and professional events
2.2 Data Collection Channels
Personal data is collected through the following channels:
- Web forms on www.dekercoet.com (contact, quotation request, account creation, newsletter subscription)
- Telephone orders
- Trade shows and professional events
- Social media interactions (Instagram, Facebook, Pinterest)
Section 3 — Purposes and Legal Bases for Processing
The table below sets out the purposes for which DE KERCOET processes personal data, the corresponding legal basis under GDPR, and the categories of data involved:
|
Purpose |
Legal Basis |
Data Categories |
|
Order management and delivery |
Performance of contract (Art. 6(1)(b) GDPR) |
Identification, order, payment |
|
Customer relationship management and after-sales service |
Performance of contract (Art. 6(1)(b) GDPR) |
Identification, order, communication |
|
Newsletters and commercial communications |
Consent (Art. 6(1)(a) GDPR) |
Email, first name |
|
Website audience measurement and improvement |
Consent (Art. 6(1)(a) GDPR) via cookies |
Browsing data |
|
Accounting and tax obligations |
Legal obligation (Art. 6(1)(c) GDPR) |
Identification, order, payment |
|
Prospecting and event follow-up |
Legitimate interest (Art. 6(1)(f) GDPR) |
Professional contact details |
|
Security and fraud prevention |
Legitimate interest (Art. 6(1)(f) GDPR) |
Identification, payment, browsing |
|
Responding to bespoke quotation requests |
Pre-contractual measures (Art. 6(1)(b) GDPR) |
Identification, dimensions, technical plans |
Section 4 — Data Recipients
4.1 DE KERCOET Internal Departments
Personal data is processed by DE KERCOET's internal departments including customer service, logistics, accounting, and management in order to fulfil the purposes described in Section 3.
4.2 Sub-processors
DE KERCOET uses carefully selected sub-processors for the following functions:
- OVHcloud (web hosting) — headquartered in France, data hosted within the European Union
- Stripe (online payment processing) — certified under the Data Privacy Framework; card data is not stored by DE KERCOET but processed directly by Stripe
- Google LLC (Google Analytics) — certified under the Data Privacy Framework for audience measurement
- The Rocket Science Group LLC (Mailchimp) — for newsletter distribution, certified under the Data Privacy Framework
- Carriers and logistics partners — receive only customer name, address, and telephone number for delivery purposes
4.3 No Commercial Data Sharing
DE KERCOET does not sell or transfer personal data to third parties for commercial purposes.
Section 5 — Data Transfers Outside the European Union
Certain data transfers to the United States occur in connection with Google Analytics and Mailchimp. These transfers are governed by the Data Privacy Framework (DPF) between the European Union and the United States, pursuant to the European Commission's adequacy decision 2023/1795.
Stripe is certified under the Data Privacy Framework and may transfer data to the United States under this same framework.
Should the Data Privacy Framework be invalidated or suspended, DE KERCOET commits to implementing Standard Contractual Clauses as alternative safeguards in accordance with Chapter V of the GDPR.
Data hosted by OVHcloud is stored in France and the European Union.
Section 6 — Data Retention Periods
Personal data is retained for the periods specified in the table below, after which it is deleted or anonymised:
|
Data Category |
Retention Period |
|
Active customer data |
Duration of relationship plus 3 years (prospecting) |
|
Order data |
10 years (French Commercial Code, Art. L.123-22) |
|
Payment data (card numbers) |
Not stored by DE KERCOET; managed by Stripe |
|
Billing data |
10 years |
|
Browsing data (Google Analytics) |
13 months (CNIL recommendation) |
|
Prospect data (events, trade shows) |
3 years from last contact |
|
Newsletter subscriber data |
Until unsubscription plus 3 years archiving |
|
Complaint and dispute data |
5 years (statutory limitation period) |
Section 7 — Data Security
7.1 Technical Measures
DE KERCOET implements the following technical security measures:
- SSL/TLS encryption of all data in transit
- Secure hosting with OVHcloud, a leading European provider with certified security standards
- Payment card data is not stored by DE KERCOET but tokenised and processed securely by Stripe
- Restricted access to personal data limited to authorised personnel
7.2 Organisational Measures
DE KERCOET implements the following organisational security measures:
- Staff training and awareness regarding data protection and security best practices
- Secure password and access control policies
- Sub-processing agreements fully compliant with Article 28 of the GDPR
7.3 Breach Notification
In the event of a data breach, DE KERCOET commits to notifying the French Data Protection Authority (CNIL) within 72 hours as required by Article 33 of the GDPR. Where there is a high risk to individuals, affected data subjects will be notified as required by Article 34 of the GDPR.
Section 8 — Rights of Data Subjects
Under GDPR Articles 15 to 22 and applicable French data protection law, individuals have the following rights regarding their personal data processed by DE KERCOET:
- Right of access: obtain confirmation that data concerning you is being processed and receive a copy of that data
- Right to rectification: request correction of inaccurate data
- Right to erasure ('right to be forgotten'): request deletion of personal data
- Right to restrict processing: request temporary suspension of data use
- Right to data portability: receive your data in a structured, machine-readable format
- Right to object: object to processing on grounds of legitimate interest or for direct marketing
- Right to withdraw consent: withdraw consent at any time without affecting the lawfulness of prior processing
- Right to define post-mortem directives: provide instructions regarding personal data after death
8.1 How to Exercise Your Rights
To exercise any of these rights, please contact DE KERCOET by:
- Email: bonjour@dekercoet.com
- Post: DE KERCOET, 13 rue des Saints-Pères, 75006 Paris, France
- Telephone: +33 9 87 88 88 69
DE KERCOET will respond to all requests within one (1) month of receipt. A valid form of identification may be requested to verify your identity.
8.2 Complaints to the Supervisory Authority
You have the right to lodge a complaint with the French Data Protection Authority (CNIL) if you believe your data protection rights have been violated. You can contact the CNIL at:
Website: www.cnil.fr
Section 9 — Cookies and Similar Tracking Technologies
For comprehensive information regarding cookies and other tracking technologies used on www.dekercoet.com, please refer to DE KERCOET's separate Cookie Management Policy available on the website. That policy details the types of cookies used, how to manage your preferences, and your rights regarding such technologies.
Section 10 — Profiling and Automated Decision-Making
DE KERCOET does not carry out any profiling or automated decision-making within the meaning of Article 22 of the GDPR.
Section 11 — Amendments to this Policy
DE KERCOET reserves the right to amend this Data Protection Policy at any time to comply with legal, regulatory, or technological developments. The date of the most recent update is indicated at the top of this document.
Users will be informed of any substantial changes to this policy. Continued use of www.dekercoet.com following the publication of changes constitutes acceptance of the revised policy.
Section 12 — Contact
For any questions regarding this Data Protection Policy or to exercise your data protection rights, please contact DE KERCOET:
- By email: bonjour@dekercoet.com
- By post: DE KERCOET, 13 rue des Saints-Pères, 75006 Paris, France
- By telephone: +33 9 87 88 88 69

