La Tourangelle – www.latourangelle.fr Last updated: June 2025

1. Introduction and Identity of the Data Controller

La Tourangelle SAS, a French oil mill based in Sarlat-la-Canéda (France), is the controller of personal data collected through the website www.latourangelle.fr (hereinafter "the Site").

We place great importance on protecting the privacy of our customers and users. This Privacy Policy informs you of how we collect, use, share, and protect your personal data, in accordance with the General Data Protection Regulation (GDPR – EU Regulation 2016/679) and the amended French Data Protection Act (Loi Informatique et Libertés).

For any questions regarding this policy or your data, you may contact us at:

  • Postal address: La Tourangelle SAS, Moulin de la Tour, 24200 Sarlat-la-Canéda, France
  • Email: contact@latourangelle.fr
  • Phone: +33 (0)5 53 59 40 14

2. Personal Data Collected

2.1 Data Collected Directly from You

As part of your browsing and purchases on the Site, we may collect the following data:

  • Identification data: last name, first name, email address, phone number
  • Delivery and billing data: full postal address
  • Payment data: banking information is processed directly by our secure payment providers (Stripe, PayPal) and is never stored on our servers
  • Customer account data: login credentials (email, encrypted password), order history
  • Communication data: messages sent via the contact form or to customer service
  • Preference data: wish lists, favourite products

2.2 Automatically Collected Data

During your browsing, we automatically collect certain technical data via cookies and trackers:

  • IP address and approximate geolocation data
  • Browser type and operating system
  • Pages visited, visit duration, browsing path
  • Access source (search engine, direct link, social networks)
  • Data relating to interactions with our emails (opens, clicks)

3. Purposes and Legal Bases for Processing

We process your personal data for the following purposes:

3.1 Performance of the Sales Contract

Legal basis: Performance of a contract (Article 6.1.b of the GDPR)

  • Processing and tracking your orders
  • Managing payments and invoicing
  • Organising delivery and parcel tracking
  • Managing returns, refunds, and complaints
  • Creating and managing your customer account

3.2 Legal Obligations

Legal basis: Legal obligation (Article 6.1.c of the GDPR)

  • Retention of accounting and tax documents (statutory period: 10 years)
  • Responding to requests from competent authorities
  • Managing withdrawal rights (14 days, in accordance with consumer law)

3.3 Legitimate Interest

Legal basis: Legitimate interest (Article 6.1.f of the GDPR)

  • Improving our products, services, and user experience
  • Fraud prevention and transaction security
  • Statistical analysis of Site traffic via Google Analytics
  • Managing customer reviews and testimonials

3.4 Consent

Legal basis: Consent (Article 6.1.a of the GDPR) – withdrawable at any time

  • Sending newsletters and personalised marketing communications
  • Placing non-essential cookies (advertising, social media, advanced analytics)
  • Sharing your data with third-party commercial partners for marketing purposes

4. Cookies and Trackers

The Site uses cookies, small text files placed on your device during browsing. You can manage your preferences via the consent banner displayed on your first visit or by accessing our cookie settings.

4.1 Strictly Necessary Cookies

These cookies are essential for the Site to function and do not require your consent:

  • Shopping cart session (PrestaShop)
  • Account authentication and security
  • Language preference storage

4.2 Analytical and Performance Cookies

With your consent, we place analytics cookies via Google Tag Manager (GTM-NPRF5V9) and Google Analytics to measure traffic and improve our services.

4.3 Social Media Cookies

Third-party cookies may be placed via the Instagram, Facebook, and LinkedIn sharing buttons integrated into the Site.

For more information on cookie management, please visit the settings page available at the bottom of the Site.

5. Data Sharing and Recipients

We never sell your personal data to third parties. Your data may be shared with the following categories of recipients:

  • Secure payment providers (Stripe, PayPal) for transaction processing
  • Carriers and logistics providers (Colissimo, Chronopost, etc.) for order delivery
  • Hosting and e-commerce solution providers (PrestaShop, OVHcloud) for Site operation
  • Marketing tools (Mailchimp or equivalent) for sending newsletters, with your consent
  • Analytics tools (Google Analytics) for traffic analysis, with your consent
  • Competent authorities (judicial, tax) upon legal request

All our subcontractors are contractually bound to uphold the confidentiality and security of your data in accordance with the GDPR.

6. Data Transfers Outside the European Union

Some of our providers (including Google, Meta/Facebook, Stripe) may be located outside the European Union, particularly in the United States. These transfers are governed by appropriate safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Certification mechanisms recognised by data protection authorities

We ensure that any transfer outside the EU is subject to a level of protection equivalent to that guaranteed within Europe.

7. Retention Periods

We retain your personal data for the following periods:

  • Active customer account data: for the duration of the commercial relationship, then 3 years after the last purchase or contact
  • Order and invoice data: 10 years (accounting and tax obligation)
  • Browsing data and analytics cookies: maximum 13 months
  • Prospect data (newsletter without purchase): 3 years from the collection of consent or last contact
  • Contact form data: 1 year after the request is closed

8. Your Rights

In accordance with the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15): obtain a copy of the data we hold about you
  • Right to rectification (Art. 16): correct inaccurate or incomplete data
  • Right to erasure (Art. 17): request the deletion of your data, subject to our legal obligations
  • Right to restriction of processing (Art. 18): temporarily restrict the use of your data
  • Right to data portability (Art. 20): receive your data in a structured, machine-readable format
  • Right to object (Art. 21): object to the processing of your data for marketing purposes or on grounds relating to your particular situation
  • Right to withdraw your consent at any time, without affecting the lawfulness of prior processing
  • Right to set directives regarding the handling of your data after your death

To exercise any of these rights, send your request by email to: contact@latourangelle.fr, specifying your identity.

You also have the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL): www.cnil.fr – 3 Place de Fontenoy, 75007 Paris.

9. Data Security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, destruction, or alteration:

  • Encryption of communications via HTTPS/SSL protocol
  • Encryption of stored passwords
  • Data access limited to authorised employees only
  • Regular security audits of our infrastructure
  • Data breach management procedures compliant with the GDPR

10. Protection of Minors

The Site is intended for an adult audience. We do not knowingly collect personal data from children under the age of 16 without the consent of their parents or legal guardians. If you believe a child has provided us with data, please contact us so that we may proceed with its deletion.

11. Amendments to This Policy

We reserve the right to modify this Privacy Policy at any time, in particular to comply with legislative and regulatory developments. The version in force is the one published on the Site, with the update date indicated in the header.

In the event of a substantial change affecting your rights, we will inform you by email or via an information banner on the Site.

12. Contact and Complaints

For any questions regarding the processing of your personal data or this policy, you may contact our team:

  • By email: contact@latourangelle.fr
  • By post: La Tourangelle SAS – Customer Service – Moulin de la Tour, 24200 Sarlat-la-Canéda
  • By phone: +33 (0)5 53 59 40 14 (Monday to Friday, 9am–5pm)

Competent supervisory authority: Commission Nationale de l'Informatique et des Libertés (CNIL) – www.cnil.fr