Skip to content

Privacy policy


Section 1 — Data Controller

DE KERCOET (DK) is the organisation responsible for the processing of personal data collected on the website www.dekercoet.com.

DE KERCOET (DK) — Limited Liability Company (SARL) with share capital of €199,970

Registered Office: 13 rue des Saints-Pères, 75006 Paris, France

RCS Paris: B 440 253 615

EU VAT number: FR 30 440 253 615

Email: bonjour@dekercoet.com — Telephone: +33 9 87 88 88 69

1.1 Data Protection Contact Point

DE KERCOET has not designated a separate Data Protection Officer (DPO). All data protection enquiries should be directed to the contact point: bonjour@dekercoet.com

Section 2 — Personal Data Collected

2.1 Categories of Personal Data Collected

DE KERCOET collects the following categories of personal data:

  • Identification data: surname, first name, postal address, email address, telephone number
  • Order data: product references, order history, bespoke furniture preferences and specifications
  • Payment data: bank card numbers are processed by our payment provider (Stripe) and are not stored by DE KERCOET; bank details for transfers are retained solely for accounting purposes
  • Browsing data: IP address, browser type, pages visited, visit duration (collected via Google Analytics)
  • Communication data: content of exchanges by email, telephone, and contact forms
  • Event data: professional contact details, business cards collected at trade shows and professional events

2.2 Data Collection Channels

Personal data is collected through the following channels:

  • Web forms on www.dekercoet.com (contact, quotation request, account creation, newsletter subscription)
  • Telephone orders
  • Trade shows and professional events
  • Social media interactions (Instagram, Facebook, Pinterest)

Section 3 — Purposes and Legal Bases for Processing

The table below sets out the purposes for which DE KERCOET processes personal data, the corresponding legal basis under GDPR, and the categories of data involved:

Purpose

Legal Basis

Data Categories

Order management and delivery

Performance of contract (Art. 6(1)(b) GDPR)

Identification, order, payment

Customer relationship management and after-sales service

Performance of contract (Art. 6(1)(b) GDPR)

Identification, order, communication

Newsletters and commercial communications

Consent (Art. 6(1)(a) GDPR)

Email, first name

Website audience measurement and improvement

Consent (Art. 6(1)(a) GDPR) via cookies

Browsing data

Accounting and tax obligations

Legal obligation (Art. 6(1)(c) GDPR)

Identification, order, payment

Prospecting and event follow-up

Legitimate interest (Art. 6(1)(f) GDPR)

Professional contact details

Security and fraud prevention

Legitimate interest (Art. 6(1)(f) GDPR)

Identification, payment, browsing

Responding to bespoke quotation requests

Pre-contractual measures (Art. 6(1)(b) GDPR)

Identification, dimensions, technical plans

Section 4 — Data Recipients

4.1 DE KERCOET Internal Departments

Personal data is processed by DE KERCOET's internal departments including customer service, logistics, accounting, and management in order to fulfil the purposes described in Section 3.

4.2 Sub-processors

DE KERCOET uses carefully selected sub-processors for the following functions:

  • OVHcloud (web hosting) — headquartered in France, data hosted within the European Union
  • Stripe (online payment processing) — certified under the Data Privacy Framework; card data is not stored by DE KERCOET but processed directly by Stripe
  • Google LLC (Google Analytics) — certified under the Data Privacy Framework for audience measurement
  • The Rocket Science Group LLC (Mailchimp) — for newsletter distribution, certified under the Data Privacy Framework
  • Carriers and logistics partners — receive only customer name, address, and telephone number for delivery purposes

4.3 No Commercial Data Sharing

DE KERCOET does not sell or transfer personal data to third parties for commercial purposes.

Section 5 — Data Transfers Outside the European Union

Certain data transfers to the United States occur in connection with Google Analytics and Mailchimp. These transfers are governed by the Data Privacy Framework (DPF) between the European Union and the United States, pursuant to the European Commission's adequacy decision 2023/1795.

Stripe is certified under the Data Privacy Framework and may transfer data to the United States under this same framework.

Should the Data Privacy Framework be invalidated or suspended, DE KERCOET commits to implementing Standard Contractual Clauses as alternative safeguards in accordance with Chapter V of the GDPR.

Data hosted by OVHcloud is stored in France and the European Union.

Section 6 — Data Retention Periods

Personal data is retained for the periods specified in the table below, after which it is deleted or anonymised:

Data Category

Retention Period

Active customer data

Duration of relationship plus 3 years (prospecting)

Order data

10 years (French Commercial Code, Art. L.123-22)

Payment data (card numbers)

Not stored by DE KERCOET; managed by Stripe

Billing data

10 years

Browsing data (Google Analytics)

13 months (CNIL recommendation)

Prospect data (events, trade shows)

3 years from last contact

Newsletter subscriber data

Until unsubscription plus 3 years archiving

Complaint and dispute data

5 years (statutory limitation period)

Section 7 — Data Security

7.1 Technical Measures

DE KERCOET implements the following technical security measures:

  • SSL/TLS encryption of all data in transit
  • Secure hosting with OVHcloud, a leading European provider with certified security standards
  • Payment card data is not stored by DE KERCOET but tokenised and processed securely by Stripe
  • Restricted access to personal data limited to authorised personnel

7.2 Organisational Measures

DE KERCOET implements the following organisational security measures:

  • Staff training and awareness regarding data protection and security best practices
  • Secure password and access control policies
  • Sub-processing agreements fully compliant with Article 28 of the GDPR

7.3 Breach Notification

In the event of a data breach, DE KERCOET commits to notifying the French Data Protection Authority (CNIL) within 72 hours as required by Article 33 of the GDPR. Where there is a high risk to individuals, affected data subjects will be notified as required by Article 34 of the GDPR.

Section 8 — Rights of Data Subjects

Under GDPR Articles 15 to 22 and applicable French data protection law, individuals have the following rights regarding their personal data processed by DE KERCOET:

  • Right of access: obtain confirmation that data concerning you is being processed and receive a copy of that data
  • Right to rectification: request correction of inaccurate data
  • Right to erasure ('right to be forgotten'): request deletion of personal data
  • Right to restrict processing: request temporary suspension of data use
  • Right to data portability: receive your data in a structured, machine-readable format
  • Right to object: object to processing on grounds of legitimate interest or for direct marketing
  • Right to withdraw consent: withdraw consent at any time without affecting the lawfulness of prior processing
  • Right to define post-mortem directives: provide instructions regarding personal data after death

8.1 How to Exercise Your Rights

To exercise any of these rights, please contact DE KERCOET by:

DE KERCOET will respond to all requests within one (1) month of receipt. A valid form of identification may be requested to verify your identity.

8.2 Complaints to the Supervisory Authority

You have the right to lodge a complaint with the French Data Protection Authority (CNIL) if you believe your data protection rights have been violated. You can contact the CNIL at:

Website: www.cnil.fr

Section 9 — Cookies and Similar Tracking Technologies

For comprehensive information regarding cookies and other tracking technologies used on www.dekercoet.com, please refer to DE KERCOET's separate Cookie Management Policy available on the website. That policy details the types of cookies used, how to manage your preferences, and your rights regarding such technologies.

Section 10 — Profiling and Automated Decision-Making

DE KERCOET does not carry out any profiling or automated decision-making within the meaning of Article 22 of the GDPR.

Section 11 — Amendments to this Policy

DE KERCOET reserves the right to amend this Data Protection Policy at any time to comply with legal, regulatory, or technological developments. The date of the most recent update is indicated at the top of this document.

Users will be informed of any substantial changes to this policy. Continued use of www.dekercoet.com following the publication of changes constitutes acceptance of the revised policy.

Section 12 — Contact

For any questions regarding this Data Protection Policy or to exercise your data protection rights, please contact DE KERCOET: