Who controls your data
The data controller is [ENTREPRENEUR LEGAL IDENTITY PENDING], Entrepreneur individuel / EI, at [OFFICIAL BUSINESS DOMICILIATION ADDRESS PENDING]. Privacy requests may be sent to [BUSINESS EMAIL PENDING].
Data we process
- The contact information you choose to provide, such as an email address, telephone or WhatsApp number, Instagram handle or Telegram handle.
- Your question, optional topic, selected package, language, optional preferred date and whether you decide the date later.
- Booking and payment status, deposit amount, package price snapshot and technical identifiers needed to prevent duplicate processing.
- The accepted terms version, acceptance time, early-performance request and booking-date snapshot needed to prove the contract choices made before payment.
- Withdrawal requests, contract or booking references and the contact email used to identify and process the request.
- Operational notification and delivery-status records used to follow up on an enquiry, payment or withdrawal request.
- A signed, browser-scoped promotion identifier and promotion timing state. Safe form drafts may also remain in your browser storage so interrupted forms can be restored.
- Basic request-security information used transiently for abuse prevention and service operation. Card details are not collected or stored by this website.
Why we use it and legal bases
- To answer enquiries and take steps requested before a booking: pre-contractual measures.
- To create, administer and fulfil a booking, confirm availability, take a deposit and handle rescheduling or refunds: performance of the contract.
- To meet accounting, consumer-law and other legal duties: legal obligation.
- To record, acknowledge and process a statutory withdrawal request: legal obligation and performance of the contract where applicable.
- To secure the service, prevent duplicate or fraudulent operations, maintain reliable records and resolve technical incidents: legitimate interests, balanced against your rights.
Service providers and recipients
Access is limited to the photographer/operator and providers needed to run the service.
- Supabase is the database processor for enquiries, bookings, legal acceptance evidence, withdrawal requests, promotion and payment-status records. Primary storage follows the selected project region; Supabase and its subprocessors may also process data in other locations under its contractual transfer safeguards. The live project region and DPA acceptance must be verified by the operator before launch.
- Stripe processes online deposits. For an EEA business, Stripe Payments Europe and relevant Stripe entities process payment and fraud-prevention data under their applicable roles and data-processing terms. Card data is handled by Stripe and is not stored by this website.
- Vercel hosts and delivers the website and processes request and security logs. Its published DPA describes primary processing in the United States and global subprocessors; the operator must verify that the live account plan is covered by that DPA before launch.
- No external email or Telegram delivery provider is active in the reviewed launch configuration. Operational events remain in the Supabase outbox until a separately reviewed delivery channel is enabled.
Advertising and CRM features not active at launch
The current production setting has advertising-attribution capture disabled. This policy does not claim active Meta CAPI, Google Enhanced Conversions, GA4, advertising pixels, advanced advertising attribution or an active HubSpot synchronization worker. If any of these are enabled later, the policy and any required consent interface must be updated first.
Concerns about a published photograph
A person who is identifiable in portfolio imagery published on this website may contact [BUSINESS EMAIL PENDING] with a concern about the use of their image.
We request only the information reasonably needed to locate the photograph, identify and contact the requester, and assess and respond to the request. Identity documents are not requested by default; further evidence may be requested only where reasonably necessary.
Each request will be reviewed promptly. Where a credible concern is raised, our operational practice is to hide the disputed image promptly while it is reviewed where practical. Reviewing or temporarily hiding an image does not determine whether the request is legally valid.
Retention
- Question-only enquiries: while answering and following up, then no longer than 12 months after the last contact; delete or anonymise afterwards unless a documented dispute or legal hold applies.
- Unpaid booking drafts and bookings abandoned or cancelled before a contract forms: while resolving the request, then no longer than 12 months after the last contact; delete or anonymise afterwards unless a documented dispute or security need applies.
- Paid bookings, payment references, commercial and terms snapshots, legal acceptances, withdrawals and cancellations after contract formation: active while the service, refund or dispute is handled, then restricted archive for 10 years after performance or termination because every offered consumer contract is at least €120 and accounting or contract evidence may have to be retained.
- Operational outbox and delivery-attempt records: until sent or finally failed and operational follow-up is complete, then no longer than 12 months; remove or anonymise payload personal data afterwards.
- Browser form drafts remain under the user’s browser controls. The essential promotion cookie lasts no more than two years. The application does not store customer photographs; a separate schedule must be added before any photo-storage or gallery feature is introduced.
International processing
Vercel’s published hosting terms describe United States and global processing. Supabase primarily stores project data in the selected project region but may process through global provider and subprocessor locations. Stripe uses relevant Stripe entities and subprocessors globally. Their published terms rely on safeguards including European Commission standard contractual clauses where required. Before launch, the operator must verify the actual Supabase region, execute or confirm the applicable provider DPAs, and retain the current transfer documentation.
Your rights
Subject to the conditions of applicable law, you may request access, correction, deletion, restriction or portability of your data, and object to processing based on legitimate interests. Contact [BUSINESS EMAIL PENDING]. You may also lodge a complaint with the French data-protection authority, the CNIL.