This policy describes how Studio Zik collects, uses, retains and protects the personal data of visitors to and customers of studiozik.com. It is drawn up pursuant to Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (GDPR), French Law No. 78-17 of 6 January 1978 as amended, and Directive 2002/58/EC ("ePrivacy") as transposed into Article 82 of that law.
1. Data controller
The controller within the meaning of Article 4(7) GDPR is:
- Studio Zik, [à compléter] incorporated under Italian law, registered office: Via del Lavoro 18, 38068 Rovereto (TN), Italie
- Partita IVA / tax code 02418590226 — REA TN-223049
- Owner of the website studiozik.com, operated under the trading name StudioZik
- Dedicated data protection contact: dpo@studiozik.com
As Studio Zik is not required to appoint a data protection officer under Article 37 GDPR, an internal data protection contact handles rights requests and maintains the record of processing activities required by Article 30 GDPR.
2. Guiding principles
Our processing operations are designed and run in accordance with the principles of Article 5 GDPR:
- Lawfulness, fairness and transparency: every processing operation rests on an identified legal basis and is brought to your attention before it is carried out.
- Purpose limitation: data is not re-used for purposes incompatible with those for which it was collected.
- Data minimisation: we collect only what is strictly necessary. Our order form asks for no date of birth, no identity document number and no information about your financial situation.
- Accuracy: you may rectify your data at any time.
- Storage limitation: each category of data has a defined retention period, set out in section 6.
- Integrity and confidentiality: the technical and organisational measures described in section 9 protect data against unauthorised access, loss and alteration.
3. Data collected
3.1 Data you provide
| Context | Data | Nature |
|---|---|---|
| Placing an order | Title, surname, first name, email address, telephone number, delivery address and, where applicable, billing address | Mandatory |
| Business order | Company name, EU VAT number | Optional |
| Order | Free-text note attached to the order | Optional |
| Contact form | Name, email address, telephone, subject, message | Mandatory except telephone |
| Newsletter | Email address, preferred language | Mandatory |
| After-sales service | Order reference, fault description, any attachments | Mandatory |
We neither collect nor store any banking data. For card payments, entry takes place entirely on a page hosted by our provider Stripe Payments Europe, Ltd.: no card number, expiry date or security code passes through our systems or is stored there. Only the card brand and its last four digits are returned to us, solely for accounting reconciliation and refund handling. For bank transfers, our records contain only the reference of the transfer received, as transmitted by our bank.
3.2 Data collected automatically
- Server technical logs: IP address, timestamp, page requested, HTTP response code, user agent. These logs are generated by the host for security and diagnostics.
- Session cookie: technical identifier required for the basket and for cross-site request forgery protection.
- Language preference: stored in a functional cookie after automatic detection of your system language or a manual choice.
- Consent record: random identifier, choices made by cookie category, policy version and date, retained as evidence in accordance with Article 7(1) GDPR.
- Analytics and advertising: only after your express consent (see section 5 and our cookie policy).
3.3 Data we do not collect
We process no data falling within the special categories of Article 9 GDPR (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic, biometric or health data, sex life or sexual orientation). We do not knowingly collect data concerning persons under 16; the sale of professional equipment is addressed to an adult audience.
4. Purposes and legal bases
| Purpose | Legal basis (Art. 6 GDPR) | Details |
|---|---|---|
| Order management: recording, reserving the item, processing payment, packing, shipping, delivery tracking | Performance of a contract — Art. 6(1)(b) | Without this data the order can be neither accepted nor delivered. |
| Issuing and retaining invoices, bookkeeping | Legal obligation — Art. 6(1)(c) | Article L. 123-22 of the French Commercial Code and Article 286 of the General Tax Code. |
| Management of warranties, withdrawal rights, returns and after-sales service | Contract and legal obligation — Art. 6(1)(b) and (c) | Articles L. 217-3 et seq. and L. 221-18 et seq. of the Consumer Code. |
| Responding to enquiries sent through the contact form | Pre-contractual measures or legitimate interests — Art. 6(1)(b) and (f) | Legitimate interest in replying to enquiries addressed to us. |
| Sending the commercial newsletter | Consent — Art. 6(1)(a) | Double opt-in, withdrawal possible at any time via the unsubscribe link. |
| Statistical audience measurement and advertising campaigns (Google Analytics 4, Google Ads, Meta Pixel) | Consent — Art. 6(1)(a) and Art. 82 of the French Data Protection Act | No non-essential tracker is set before you accept. |
| Site security, fraud and abuse prevention, logging | Legitimate interests — Art. 6(1)(f) | Interest in protecting our systems, our customers and our stock. |
| Establishment, exercise or defence of legal claims | Legitimate interests — Art. 6(1)(f) | Held in restricted-access intermediate archive. |
Where processing rests on legitimate interests, a balancing test has been carried out between that interest and your fundamental rights and freedoms. Details of that assessment can be provided on reasoned request to dpo@studiozik.com.
5. Cookies and trackers
On your first visit, a banner lets you accept, reject or fine-tune trackers that are not strictly necessary. Rejecting is as simple as accepting: both actions are available at the same level, in a single click. No non-exempt analytics cookie, no advertising pixel and no third-party tracker is set until you have given consent.
Your choice is retained for six months, after which the banner is shown again. You may change it at any time through the "Manage cookies" link in the footer. Details of categories, purposes, recipients and durations appear in our cookie policy.
When you accept advertising trackers, Google Consent Mode v2 is activated: the ad_storage, ad_user_data, ad_personalization and analytics_storage signals are transmitted in line with your choice. If you refuse, those signals are set to denied and no identifying data is transmitted.
6. Retention periods
| Category | Active database | Archiving |
|---|---|---|
| Order and delivery data | 3 years from the last order | Intermediate archive until limitation periods expire |
| Invoices and accounting records | — | 10 years (Art. L. 123-22 French Commercial Code) |
| Warranty and after-sales files | Warranty period + 2 years | 5 years (general limitation period) |
| Contact form messages | 12 months from the last exchange | — |
| Newsletter subscribers | 3 years from the last active contact | — |
| Cookie consent evidence | 6 months (consent lifetime) | 36 months as evidence |
| Server technical logs | 6 months | — |
| Analytics (pseudonymous identifiers) | 14 months maximum | — |
On expiry of these periods, data is irreversibly deleted or anonymised so that no re-identification is possible.
7. Recipients and processors
Your data is accessible, to the extent necessary for their duties, to authorised staff of Studio Zik responsible for order preparation, accounting and customer service. It is also disclosed to the following categories of recipient:
| Recipient | Role | Data transmitted | Location |
|---|---|---|---|
| Host (OVHcloud) | Processor — hosting and backup | All site data | European Union |
| Carriers (DPD, Chronopost, GLS, DHL depending on destination) | Independent recipient — carriage | Name, address, telephone, email, parcel weight and dimensions | EU / destination country |
| Stripe Payments Europe, Ltd. | Processor — card payment processing | Name, email address, amount, order reference, card data entered directly with Stripe | Ireland |
| Bank | Independent recipient — receipt of the transfer | Payer name, reference, amount | European Union |
| Accountant and statutory auditor | Independent recipient — accounting obligations | Invoices and entries | France |
| Transactional email provider | Processor | Email address, name, message content | European Union |
| Google Ireland Ltd (Analytics, Ads) | Processor / joint controller depending on the feature | Pseudonymous identifiers, browsing events | Ireland, with framed transfers to the United States |
| Meta Platforms Ireland Ltd (Pixel) | Joint controller | Pseudonymous identifiers, browsing events | Ireland, with framed transfers to the United States |
Each processor is bound by a contract compliant with Article 28 GDPR, imposing confidentiality, security, assistance with rights requests and a prohibition on unauthorised sub-processing. Your data is never sold, rented or exchanged for third-party marketing purposes.
8. Transfers outside the European Union
Data required to perform your order is hosted and processed within the European Union.
Analytics and advertising tools, activated only after your consent, may involve a transfer to the United States. Those transfers are framed by:
- the European Commission adequacy decision of 10 July 2023 on the EU–US Data Privacy Framework, for certified organisations;
- in the alternative, the standard contractual clauses adopted by Implementing Decision (EU) 2021/914, supplemented by additional technical and organisational measures.
If you refuse advertising and analytics cookies, no transfer of your data outside the European Union takes place.
9. Security
In accordance with Article 32 GDPR, we implement technical and organisational measures appropriate to the risk:
- systematic encryption of exchanges using TLS 1.2 or above (forced HTTPS, HSTS header);
- administrator passwords hashed with an adaptive-cost algorithm;
- segregated administration area, mandatory authentication, access logging;
- protection against cross-site request forgery, SQL injection and script injection;
- content security policy and HTTP security headers;
- daily encrypted backups held in isolation and tested periodically;
- least-privilege access management and periodic account review;
- security updates applied within a controlled timeframe after release.
In the event of a data breach likely to result in a risk to your rights and freedoms, we notify the French supervisory authority within 72 hours pursuant to Article 33 GDPR and inform you individually without undue delay where the risk is high, pursuant to Article 34.
10. Your rights
Subject to the conditions of Articles 15 to 22 GDPR you have the following rights:
- Right of access (Art. 15): obtain confirmation that data concerning you is processed and receive a copy of it.
- Right to rectification (Art. 16): have inaccurate data corrected or incomplete data completed.
- Right to erasure (Art. 17): obtain deletion of your data, except where retention is necessary to comply with a legal obligation — in particular accounting — or for the establishment, exercise or defence of legal claims.
- Right to restriction (Art. 18): request the temporary freezing of contested processing.
- Right to data portability (Art. 20): receive the data you provided in a structured, commonly used, machine-readable format and transmit it to another controller.
- Right to object (Art. 21): object at any time, on grounds relating to your particular situation, to processing based on legitimate interests; and without having to give reasons where processing is for direct marketing.
- Right to withdraw consent (Art. 7(3)) at any time, without affecting the lawfulness of processing carried out beforehand.
- Right to give directions as to the fate of your data after your death (Art. 85 of the French Data Protection Act).
No decision producing legal effects concerning you is taken solely on the basis of automated processing, including profiling, within the meaning of Article 22 GDPR.
10.1 How to exercise your rights
Send your request to dpo@studiozik.com or by post to Studio Zik — Data Protection, Via del Lavoro 18, 38068 Rovereto (TN), Italie.
We reply within one month of receipt, extendable by two months where the request is complex or numerous; you would be informed within the initial month. Where reasonable doubt remains as to your identity, we may request an additional verification element, proportionate and limited to that sole purpose.
10.2 Complaint to a supervisory authority
If, after contacting us, you consider that your rights are not being respected, you may lodge a complaint with the supervisory authority of your Member State of residence:
- France — CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr
- Spain — Agencia Española de Protección de Datos (AEPD) — www.aepd.es
- Italy — Garante per la protezione dei dati personali — www.garanteprivacy.it
- Germany — BfDI and the Länder authorities — www.bfdi.bund.de
- United Kingdom — Information Commissioner's Office (ICO) — ico.org.uk
11. Direct marketing
The newsletter is sent only after your explicit confirmation (double opt-in). Every message carries a working unsubscribe link, active for the whole subscription period. Unsubscription is processed immediately and unconditionally.
Under Article L. 34-5 of the French Postal and Electronic Communications Code, if you have already placed an order we may send you offers relating to products similar to those you purchased, provided that each message offers you the opportunity to object.
12. Changes to this policy
This policy may be updated to reflect legislative, case-law, technical or organisational developments. Where a substantial change affects your rights you will be informed by a visible notice on the site and, where consent-based processing is concerned, your consent will be collected again.
Version in force: 2026-09-01.