Privacy policy
Article 1: General Overview, Organizational Structure, and Roles of the Parties
This Privacy Policy establishes the rules governing the collection, processing, use, storage, and protection of personal data of users accessing the website www.coffeeisland.fr and the mobile application My Coffee Island (hereinafter collectively referred to as the "Platform"), in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation - GDPR) and Law No. 78-17 of 6 January 1978 on Information Technology, Files and Civil Liberties, as amended (the "French Data Protection Act" / "Loi Informatique et Libertés").
1.1 Dual Responsibility Structure (Data Controllers)
The processing of personal data across the Platform operates under a joint operational framework involving two distinct entities:
· COFFEE ISLAND SWISS LTD: A corporation organized under the laws of Cyprus, having its registered office in Nicosia, Cyprus. Coffee Island Swiss Ltd acts as Data Controller (or Joint Controller where applicable) responsible for central digital infrastructure, development, maintenance, and hosting of the Platform, centralized user account administration, central databases, global loyalty program management (Coffee Island Rewards), and central digital marketing activities.
· Local Franchised Stores in France: Independent corporate entities operating under franchise agreements with Coffee Island in France. Each local franchised store acts as an independent Data Controller (or Joint Controller for local order fulfillment) regarding the processing of personal data necessary for preparing orders, local product delivery or in-store pickup, local billing, tax compliance, and local store customer service.
Article 2: Categories of Personal Data Collected
Depending on how users interact with the Platform, the following categories of personal data are collected and processed:
2.1 Identity and Account Profile Data
When creating a user profile or placing an order, collected data includes full name, email address, mobile phone number, birth date (optional, used for promotional offers such as birthday rewards), preferred language, and account login credentials (encrypted password).
2.2 Transactional and Order Execution Data
Details concerning products purchased, order history, selected delivery address, local franchise store selected, transaction timestamps, payment receipts, and earned or redeemed loyalty points. Note on Payment Data: Payment card numbers and banking credentials are collected and processed directly by certified Payment Service Providers (PSPs) compliant with PCI-DSS standards. Coffee Island does not store complete banking or credit card details on its servers.
2.3 Technical, Device, and Browsing Data
IP address, device hardware model, operating system version, browser type, unique device identifiers, access timestamps, referrer URLs, and precise or approximate geolocation data (subject to user authorization for locating nearby stores).
2.4 Communications and Support Data
Content of inquiries sent through contact forms, customer service emails, feedback, ratings, and survey responses.
Article 3: Legal Bases and Purposes of Data Processing
Personal data is collected exclusively for specified, explicit, and legitimate purposes, grounded in the legal bases defined by Article 6 of the GDPR:
|
Processing Purpose |
Legal Basis (GDPR) |
Categories of Data |
|
User account creation, management, order processing, delivery, and customer support. |
Article 6(1)(b) GDPR |
Identity, Transactional, Account Profile, Contact Data. |
|
Compliance with statutory accounting, invoicing, tax, and commercial reporting obligations in France. |
Article 6(1)(c) GDPR |
Transactional Data, Invoices, Billing Addresses, Order History. |
|
Security monitoring, fraud prevention, Platform performance optimization, and quality control. |
Article 6(1)(f) GDPR |
Technical Data, Device Identifiers, IP Logs, Usage Analytics. |
|
Commercial marketing, newsletter dispatch, push notifications, and non-essential cookies. |
Article 6(1)(a) GDPR |
Email Address, Mobile Phone, Marketing Preferences, Cookie Identifiers. |
Article 4: Communication and Recipients of Personal Data
Personal data collected through the Platform is not sold, rented, or traded to third parties. Data is shared exclusively with authorized recipients under the following conditions:
· Local Franchised Stores in France: Relevant order details are communicated to the specific store selected by the user to enable preparation, fulfillment, local pickup, or delivery.
· Subcontractors and Data Processors (Article 28 GDPR): Data is shared with specialized service providers acting on behalf of Coffee Island under strict data processing agreements. These include cloud hosting providers, IT infrastructure maintainers, payment gateways, email/SMS delivery platform operators, and logistics/courier partners.
· Public Authorities and Judicial Bodies: Data may be disclosed to competent administrative, judicial, or law enforcement authorities in France when mandated by law or pursuant to a binding administrative or court order.
Article 5: International Data Transfers
Personal data is primarily stored and processed on servers located within the European Economic Area (EEA). If any technical service provider transfers data outside the EEA, Coffee Island ensures that such transfers comply strictly with Chapter V of the GDPR by implementing appropriate safeguards, such as European Commission Standard Contractual Clauses (SCCs) or reliance on European Commission adequacy decisions (such as the EU-U.S. Data Privacy Framework).
Article 6: Data Retention Periods
Personal data is retained only for the duration necessary to fulfill the purposes for which it was collected, or as required by statutory retention periods under French law:
· User Account Data: Retained for the active lifetime of the user account. Accounts inactive for two (2) consecutive years will be deleted or anonymized following prior notice sent to the user.
· Commercial and Tax Records (France): Invoices, transaction details, and accounting records are retained for ten (10) years pursuant to Article L123-22 of the French Commercial Code (Code de commerce) and six (6) years for tax inspection purposes pursuant to Article L102 B of the Book of Tax Procedures (Livre des procédures fiscales).
· Direct Marketing Data: Retained until consent is withdrawn or for a maximum period of three (3) years from the last active contact initiated by the customer.
· Technical Logs and Identifiers: Retained for a maximum duration of six (6) to twelve (12) months.
Article 7: Rights of Data Subjects (GDPR & French Law)
Pursuant to Articles 15 to 22 of the GDPR and the French Data Protection Act (Loi Informatique et Libertés), users possess the following statutory rights:
· Right of Access (Art. 15 GDPR): Obtain confirmation as to whether personal data is being processed and receive a copy of such data.
· Right to Rectification (Art. 16 GDPR): Request the immediate correction of inaccurate or incomplete personal data.
· Right to Erasure / Right to be Forgotten (Art. 17 GDPR): Obtain the deletion of personal data when it is no longer necessary or when consent is withdrawn.
· Right to Restriction of Processing (Art. 18 GDPR): Request the limitation of processing under statutory legal grounds.
· Right to Data Portability (Art. 20 GDPR): Receive personal data in a structured, commonly used, and machine-readable format to transmit it to another controller.
· Right to Object (Art. 21 GDPR): Object at any time to processing based on legitimate interests or for direct marketing purposes.
· Right to Withdraw Consent (Art. 7(3) GDPR): Withdraw consent at any time without affecting the lawfulness of processing based on consent prior to withdrawal.
· Right to Post-Mortem Directives (Art. 85 French Data Protection Act): Define general or specific directives regarding the retention, erasure, and communication of personal data after death.
Article 8: Exercise of Rights and Supervisory Authority
Users may exercise their data protection rights at any time by contacting the Data Protection Team via email at privacy@coffeeisland.fr or by postal mail addressed to Coffee Island Swiss Ltd / Coffee Island France Customer Care.
If a user considers that the processing of their personal data constitutes a violation of applicable data protection regulations, they have the statutory right to lodge a formal complaint with the competent supervisory authority in France:
|
Commission Nationale de l'Informatique et des Libertés (CNIL) |