Skip to content

Free delivery in Île-de-France · Anywhere in France on quote · Order from 24 hours

Privacy Policy

Courtesy translation. Only the French version is legally binding: in the event of any difference of interpretation, the French text prevails. Read the French version.

The purpose of this Privacy Policy (the "Policy") is to inform, transparently, fairly and fully, the natural persons whose personal data is processed in connection with browsing the website www.crozytraiteur.fr, requesting, drawing up and electronically signing quotes, placing, preparing and performing orders for catering services, invoicing, and any commercial or pre-contractual relationship with the sole trader VENDORA, operating the trade name "Crozy" ("Vendora").

This Policy is drawn up in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "GDPR"), with French Act no. 78-17 of 6 January 1978 as amended on data processing, data files and individual liberties (the "French Data Protection Act"), and with French Act no. 2004-575 of 21 June 2004 on confidence in the digital economy ("LCEN"). It supplements, without replacing, the General Terms and Conditions of Sale and the legal notice of the site, to which it refers for everything concerning the commercial, contractual and liability conditions of the relationship between Vendora and its clients.

Vendora carries on a catering business aimed at companies and professionals (B2B): office breakfasts, coffee breaks, buffets, cocktail receptions, individual meal trays and seminar services, delivered in Île-de-France, set-up on site being an option, from perishable foodstuffs made to order. In that context, most of the data processed relates to professional contacts acting on behalf of client companies. Vendora may nevertheless process data relating to natural persons (representatives, staff, contacts, delivery recipients) and applies to that data all the safeguards described below.

Vendora is a sole trader (EI) covered by the VAT exemption scheme provided for in Article 293 B of the French General Tax Code: accordingly Vendora does not charge value added tax, its prices are expressed as net amounts, and its invoices carry the statement "TVA non applicable, article 293 B du CGI". This is stated for information and has no bearing on the nature of the processing described in this Policy.

Orders are placed by way of an online quote. Electronic signature of the quote ("bon pour accord", approval to order) constitutes a firm and final commitment to order and to pay; it is time-stamped and has evidential value in accordance with Articles 1366 and 1367 of the French Civil Code and the eIDAS Regulation (EU) no. 910/2014. As the goods are perishable foodstuffs made to order according to the customer's specifications and the clientele is professional, no right of withdrawal applies, in accordance with Article L. 221-28, 3° and 4°, of the French Consumer Code; the details of that commitment are set out in the General Terms and Conditions of Sale and are recalled here to ensure the consistency of the processing relating to proof of commitment.

By browsing www.crozytraiteur.fr, requesting a quote, electronically signing a quote or placing an order, the data subject acknowledges having read this Policy. It may be supplemented by specific information provided when certain data is collected. The date of last update appears at the top or the bottom of the document; the applicable version is the one in force and available on the site at the time of consultation or of collection of the data.

Article 1 - Data controller and contact details

The controller of the personal data, within the meaning of Article 4(7) of the GDPR, is the sole trader VENDORA, operating the trade name "Crozy", whose registered office is at 9 rue des Colonnes, 75002 Paris.

Vendora is identified by SIREN number 511 866 030 and SIRET number (registered office) 511 866 030 00048, APE code 10.72Z. Vendora is represented by the manager of the sole trader Vendora, who determines the purposes and means of the processing described in this Policy.

Any question concerning this Policy, and any request to exercise the rights set out in Articles 12 and 13, may be sent: electronically, to contact@crozytraiteur.fr; by post, to VENDORA, 9 rue des Colonnes, 75002 Paris.

Given the nature of its activities and the volume of its processing, Vendora is not legally required to appoint a data protection officer (DPO) within the meaning of Article 37 of the GDPR. The manager of the sole trader Vendora directly oversees compliance and is the single point of contact for any question relating to data protection.

Article 2 - Scope, definitions and relationship with the other documents

This Policy applies to all processing of personal data carried out by Vendora in connection with operating the website www.crozytraiteur.fr, managing quote requests, concluding and performing catering service contracts, invoicing, after-sales service, managing the client relationship and, where applicable, commercial marketing.

For the purposes of this Policy: "personal data" means any information relating to an identified or identifiable natural person; "processing" means any operation performed on personal data (collection, recording, storage, consultation, use, communication, erasure, and so on); "data subject" means the natural person to whom the data relates; "controller" means the person who determines the purposes and means of the processing; "processor" means the natural or legal person who processes data on behalf of the controller; "recipient" means the person to whom the data is disclosed; "consent" means any freely given, specific, informed and unambiguous indication of the data subject's wishes; "profiling" means any form of automated processing intended to evaluate certain personal aspects of a natural person; "personal data breach" means any breach of security leading to the destruction, loss, alteration, unauthorised disclosure of, or access to, data.

As Vendora's clientele consists of legal entities (companies) and professionals, the data processed mainly concerns natural persons acting as the representative, employee, member of staff or contact of a client entity. Data relating to legal entities as such (company name, SIRET, and so on) does not constitute personal data, except where it identifies a natural person, in particular for sole traders and self-employed professionals.

This Policy supplements the General Terms and Conditions of Sale and the legal notice of the site. In the event of a conflict relating specifically to the processing of personal data, the provisions of this Policy prevail; for any other question, the General Terms and Conditions of Sale remain applicable.

Article 3 - Categories of personal data collected

In the course of its activities, Vendora may collect and process the following categories of data.

Identity and professional contact data: title, surname, first name, role or position within the client company, professional e-mail address, professional telephone number.

Data relating to the client company which identifies a natural person: company or trading name, SIRET/SIREN number, establishment address, information from public company databases (the French company register / SIRENE database), where those items relate to a natural person (sole trader, self-employed professional, director).

Address data: billing address, delivery address and place, access information for the delivery site (floor, building, on-site contact, access instructions), which may be standardised via an address autocomplete service.

Data relating to quotes and orders: content and references of quotes, menus and services selected, number of guests, delivery dates and slots chosen, net amounts, history of exchanges, notes and any specific instructions.

Data relating to the electronic signature of the quote: acceptance of the quote ("bon pour accord") constituting a firm and final commitment, time stamp of the signature, IP address and technical data associated with the signature operation, session identification elements, which constitute the evidence of the commitment within the meaning of Articles 1366 and 1367 of the French Civil Code and the eIDAS Regulation (EU) no. 910/2014.

Payment data: payment method chosen (bank card or transfer), net amount, date and status of the payment, transaction reference. Bank card data (number, expiry date, security code) is collected and processed directly by the payment provider Stripe in a secure environment compliant with the PCI-DSS standard; Vendora does not have access to full card numbers and does not store them.

Data relating to the client account and authentication: login credentials, e-mail address, password hash (the password is never stored or transmitted in clear), history of quotes and orders attached to the account.

Data relating to allergens and food information: requests, preferences or constraints communicated by the client concerning the fourteen allergenic substances which must be declared (Regulation (EU) no. 1169/2011, the "FIC Regulation"). This data is processed only so far as strictly necessary to perform the service and does not constitute, in a B2B context, a collection of health data within the meaning of Article 9 of the GDPR. Vendora invites data subjects not to send it health data; where such data is sent spontaneously by the client, it is processed only so far as strictly necessary for the safety of the service.

Technical and browsing data: IP address, browser type and version, operating system, pages viewed, date and time of connection, connection logs, data from cookies and trackers under the conditions set out in Article 15.

Client relationship and correspondence data: content of e-mails, messages, complaints, after-sales requests and feedback.

Vendora does not knowingly collect data falling within the special categories referred to in Article 9 of the GDPR (so-called sensitive data) and invites data subjects not to send it such data beyond what is strictly necessary for the service.

Article 4 - Source of the data and the client's warranties

The data processed by Vendora is, in the great majority of cases, collected directly from the data subject or the client company, when it requests a quote, creates an account, electronically signs a quote, places an order, makes a payment, or communicates with Vendora by e-mail, telephone or any other means.

Certain data relating to the client company may be supplemented from public and official sources, in particular the French company register and the SIRENE database, solely for the purposes of verification, improving the reliability of billing information and securing the commercial relationship.

Where a contact, a member of staff or a delivery recipient is entered by the client without being the direct author of the order, the corresponding data is processed on the basis of Vendora's legitimate interest in performing the service. A client who provides Vendora with data relating to third parties (representatives, employees, on-site contacts, delivery recipients, guests) warrants that it is authorised to pass it on and that it has previously informed the data subjects of the processing of their data by Vendora for the purposes of performing the service, and of the existence of this Policy.

The client warrants the accuracy, honesty and currency of the data it provides. Vendora may not be held liable for the consequences of erroneous, incomplete or out-of-date data provided by the client or by persons acting on its behalf.

Article 5 - Purposes of the processing and legal bases

Each processing operation carried out by Vendora rests on a specific legal basis within the meaning of Article 6 of the GDPR. The purposes and legal bases are set out below.

Managing quote requests and the pre-contractual relationship (drawing up, sending and following up quotes, answering information requests): legal basis - performance of pre-contractual measures taken at the data subject's request (Article 6(1)(b) GDPR).

Concluding and performing the catering service contract (electronic signature of the quote constituting a firm and final commitment, preparing and making the food, organising delivery and set-up, managing delivery slots, taking declared allergens into account): legal basis - performance of the contract to which the data subject or the company they represent is a party (Article 6(1)(b) GDPR). Given the perishable nature of the food, made to order according to the client's specifications, and the professional nature of the relationship, the commitment is firm and final and gives no right of withdrawal (Article L. 221-28, 3° and 4°, of the French Consumer Code).

Collecting and retaining evidence of the commitment (time stamping, logging and archiving the electronic signature of the "bon pour accord" quote): legal basis - performance of the contract and Vendora's legitimate interest in establishing, exercising and defending its rights (Article 6(1)(b) and (f) GDPR), in accordance with Articles 1366 and 1367 of the French Civil Code and the eIDAS Regulation (EU) no. 910/2014.

Managing payments and preventing non-payment and fraud (collection by bank card via Stripe or by transfer, reminders, recovery): legal basis - performance of the contract (Article 6(1)(b) GDPR) and Vendora's legitimate interest in securing its transactions and preventing fraud (Article 6(1)(f) GDPR).

Invoicing and compliance with accounting, tax and legal obligations (issuing and keeping invoices carrying the statement "TVA non applicable, article 293 B du CGI", bookkeeping, responding to requests from the competent authorities): legal basis - compliance with a legal obligation to which Vendora is subject (Article 6(1)(c) GDPR), in particular under the French Commercial Code and the French Tax Procedure Code.

Managing the client account and personal area (creating and administering the account, secure authentication, access to the history of quotes and orders): legal basis - performance of the contract and legitimate interest in providing a reliable and secure online service (Article 6(1)(b) and (f) GDPR).

Managing the client relationship, after-sales service and complaints (handling requests, returns and disputes): legal basis - performance of the contract and Vendora's legitimate interest in ensuring the quality of its services and following up its clientele (Article 6(1)(b) and (f) GDPR).

Publishing client reviews (rating, comment, first name and, where applicable, company): legal basis - consent (Article 6(1)(a) GDPR), obtained when the review is submitted.

Sending transactional and operational communications by e-mail and, at the client's choice, by text message (SMS) (quote, order and payment confirmations, delivery information, password reset e-mails), the signature confirmation code being sent by e-mail and by text message: legal basis - performance of the contract (Article 6(1)(b) GDPR).

Commercial marketing and sending information about Vendora's services (under the conditions of Article 16): legal basis - Vendora's legitimate interest in promoting its services to its professional clientele for similar products or services (Article 6(1)(f) GDPR), or the data subject's consent where that is required (Article 6(1)(a) GDPR).

Audience measurement, improvement and security of the site (traffic statistics, prevention of fraudulent or abusive use, cookie management): legal basis - consent for trackers that are not strictly necessary (Article 6(1)(a) GDPR and Article 82 of the French Data Protection Act) and legitimate interest for trackers strictly necessary for the operation and security of the site and for the internal traffic measurement described in Article 15 (Article 6(1)(f) GDPR).

Handling requests to exercise rights and complying with data protection obligations: legal basis - compliance with a legal obligation (Article 6(1)(c) GDPR).

Where processing rests on Vendora's legitimate interest, it is carried out only after balancing that interest against the rights, freedoms and reasonable expectations of the data subjects; the latter retain the right to object under the conditions set out in Article 12.

Article 6 - Whether providing the data is mandatory or optional

The data marked as mandatory when collected (in particular identity and professional contact details, information about the client company, billing and delivery address, data needed to prepare and deliver the service, payment data) is essential for drawing up the quote, concluding the contract and performing the service. Without that data, Vendora would not be able to handle the request, prepare the food, arrange delivery or issue the corresponding invoice.

The other data is optional and intended to improve the quality of the service or to meet the client's needs more precisely. Not providing it has no effect on the conclusion of the contract.

As regards information about allergens and dietary constraints, it is for the client to provide Vendora, in good time and in full, with all the information needed for the proper performance of the service in compliance with Regulation (EU) no. 1169/2011. The absence, inaccuracy or lateness of such information releases Vendora from any liability in that respect, without prejudice to the hygiene rules of the European Hygiene Package and the HACCP method applied by Vendora.

Article 7 - Recipients of the data and use of processors

The personal data processed by Vendora is intended for the manager of the sole trader Vendora and, where applicable, for the persons involved, under their authority, in preparing, delivering and setting up the services, in administrative, accounting and commercial management, and in after-sales service. Access to the data is limited to those persons who need to know it in order to carry out the purposes described.

To carry out its processing, Vendora uses technical providers acting as processors within the meaning of Article 28 of the GDPR. Those processors act only on Vendora's documented instructions, are bound by a duty of confidentiality and provide sufficient guarantees as to the implementation of appropriate technical and organisational measures. The processors used by Vendora are as follows.

Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, United States: hosting of the website www.crozytraiteur.fr. Transfers outside the European Union are governed by standard contractual clauses. The domain name and the mail service are managed by LWS - Ligne Web Services (France).

Neon: supply and hosting of the application database (account, quote and order data and associated items). The data is hosted in the Frankfurt region, Germany (European Union).

Stripe: payment services provider, responsible for collecting and securely processing bank card payments and for fraud prevention. Stripe processes bank card data directly in an environment compliant with the PCI-DSS standard.

Brevo (France): sending of text messages (SMS) (signature confirmation code, quotes and order information where the client has chosen that channel).

LWS - Ligne Web Services (France): mail service and routing of e-mails.

Google: Google Analytics audience measurement, only after consent.

A provider of software services assisting with the handling of requests and the drafting of quotes and correspondence (United States, transfers safeguarded under the conditions of Article 9).

Apart from those processors, the data may be disclosed, so far as necessary: to Vendora's accountants, auditors and advisers; to banks and debt recovery providers; to administrative, tax and judicial authorities and to officers of the court where disclosure is required by law or necessary to establish, exercise or defend a legal right.

Vendora does not sell, rent or transfer personal data to third parties for commercial purposes.

Article 8 - Hosting and location of the data

The website www.crozytraiteur.fr is hosted by Vercel Inc. (United States), whose hosting infrastructure is global; transfers of data outside the European Union are governed by standard contractual clauses. The domain name and the mail service are managed by LWS - Ligne Web Services (France).

The application database is hosted by the provider Neon in its Frankfurt region (Germany), within the European Union.

Vendora therefore favours hosting and storing data within the European Union, providing the level of protection guaranteed by the GDPR. Processing that may involve a transfer of data outside the European Union is governed by the conditions set out in Article 9.

Article 9 - Transfers of data outside the European Union

Vendora endeavours to keep the processing and storage of personal data within the European Union. However, certain processors, in particular the host Vercel, the payment provider Stripe, the Google Analytics service (after consent) and the provider of software services assisting with the handling of requests and the drafting of quotes and correspondence, may process data or use infrastructure or affiliated companies located outside the European Union, in particular in the United States.

Any transfer of data outside the European Union is governed by appropriate safeguards within the meaning of Articles 44 et seq. of the GDPR, namely, as the case may be: an adequacy decision of the European Commission; the provider's participation in the EU-US Data Privacy Framework; or the conclusion of standard contractual clauses adopted by the European Commission, supplemented where appropriate by additional technical and organisational measures.

Data subjects may obtain a copy of the safeguards put in place, or information about where they have been made available, by sending a request to contact@crozytraiteur.fr.

Article 10 - Data retention periods

Personal data is kept only for the period strictly necessary for the purposes for which it is processed, extended where applicable by the retention periods required by law or corresponding to the applicable limitation periods. Retention periods are determined by category as follows.

Data relating to quote requests not followed by an order: kept for the time needed to handle the request, then for a maximum of three (3) years from the data subject's last contact, for the purposes of following up the commercial relationship.

Data relating to contracts, signed quotes and completed orders: kept for the whole duration of the contractual relationship, then archived for the period needed to handle any complaints and to establish, exercise or defend a legal right, within the applicable limitation periods (in principle five years, Article 2224 of the French Civil Code).

Evidence of the electronic signature of the quote (time stamp, logs, associated technical data): kept for the duration of the contractual relationship and until the limitation periods applicable to the corresponding actions expire, in order to preserve the evidential value of the commitment.

Invoices and accounting records: kept for ten (10) years from the close of the accounting year concerned, in accordance with Article L. 123-22 of the French Commercial Code, without prejudice to the retention periods laid down by tax legislation.

Client account data: kept for the whole life of the account, then deleted or anonymised after a period of inactivity, or at the data subject's request, subject to legal retention obligations.

Commercial marketing data: kept for three (3) years from the data subject's last contact (click, reply, last purchase), or until consent is withdrawn or the right to object is exercised.

Connection logs and technical data capable of allowing identification: kept for the time needed for the security of the site and, as regards connection data, within the periods laid down by the retention obligations applicable to online service providers.

Technical data and trackers (cookies): kept under the conditions set out in Article 15, cookies not being kept beyond thirteen (13) months and the information collected through them not being kept beyond twenty-five (25) months.

Data relating to the handling of requests to exercise rights and any identity documents provided: kept for the time needed to handle the request, then for the applicable limitation period in the event of litigation.

When the applicable periods expire, the data is deleted, irreversibly anonymised, or archived for evidential purposes in a restricted-access environment for the sole period needed to comply with legal obligations and to defend Vendora's rights.

Article 11 - Security, confidentiality and record of processing activities

Vendora implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk and to protect personal data against destruction, loss, alteration, unauthorised disclosure or access, in accordance with Article 32 of the GDPR.

Those measures include in particular: encryption of data exchanges via the HTTPS/TLS protocol; storage of passwords as non-reversible hashes, passwords never being stored or transmitted in clear; the use of secure authentication cookies; limiting and controlling access to data to authorised persons only; the use of processors with proven security guarantees; logging of sensitive operations, in particular the electronic signature of quotes and changes in the status of orders and payments.

Bank card payments are processed by the provider Stripe in an environment compliant with the PCI-DSS standard; Vendora never has access to the data subject's full bank card details.

Vendora maintains, so far as the regulations require, a record of processing activities within the meaning of Article 30 of the GDPR, describing the processing carried out, its purposes, the categories of data and recipients and the retention periods.

In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, Vendora undertakes to notify that breach to the French data protection authority (CNIL) under the conditions and within the time limits laid down in Article 33 of the GDPR and, where the breach is likely to result in a high risk, to inform the data subjects in accordance with Article 34 of the GDPR.

Notwithstanding the measures implemented, the data subject acknowledges that no electronic transmission of data can be absolutely guaranteed; it is for them to keep their login credentials confidential and not to disclose them to third parties.

Article 12 - Data subjects' rights

In accordance with the GDPR and the French Data Protection Act, every data subject has, under the conditions laid down by those texts, the following rights over their personal data.

Right of access (Article 15 GDPR): the right to obtain confirmation as to whether or not data concerning them is being processed and, where it is, to obtain a copy of it together with information about the processing.

Right to rectification (Article 16 GDPR): the right to have inaccurate data corrected and incomplete data completed.

Right to erasure (Article 17 GDPR): the right to have their data erased in the cases provided for by the GDPR, that right not being able to override Vendora's legal retention obligations, in particular accounting and tax obligations (keeping invoices for ten years), or the establishment, exercise or defence of a legal right.

Right to restriction of processing (Article 18 GDPR): the right to obtain restriction of processing in the cases provided for by the GDPR, in particular where the accuracy of the data is contested.

Right to object (Article 21 GDPR): the right to object at any time, on grounds relating to their particular situation, to processing based on Vendora's legitimate interest, and the right to object at any time, without giving reasons, to the processing of their data for commercial marketing purposes.

Right to portability (Article 20 GDPR): the right to receive the data they have provided, in a structured, commonly used and machine-readable format, and to transmit it to another controller, where the processing is based on consent or on the contract and is carried out by automated means.

Right to withdraw consent (Article 7 GDPR): where the processing is based on consent, the right to withdraw it at any time, without that withdrawal affecting the lawfulness of processing carried out beforehand.

Right to give directions concerning what happens to their data after their death: in accordance with Article 85 of the French Data Protection Act, any person may give general or specific directions concerning the retention, erasure and disclosure of their data after their death, and appoint a person to carry them out; those directions may be registered with a certified digital trusted third party and sent to Vendora.

These rights are exercised within the limits and subject to the reservations laid down by the applicable regulations, in particular where a legal obligation or a compelling legitimate ground justifies keeping the data or continuing the processing.

Article 13 - How to exercise your rights

The data subject may exercise their rights by sending a request, accompanied where applicable by anything allowing Vendora to identify the processing concerned: by e-mail to contact@crozytraiteur.fr; or by post to VENDORA, 9 rue des Colonnes, 75002 Paris.

Where there is reasonable doubt about the identity of the person making the request, Vendora may ask for any necessary proof of identity, in compliance with the principle of data minimisation. That proof will be used only to handle the request and will be kept in accordance with Article 10.

Vendora undertakes to reply to any request to exercise rights within one (1) month of receipt. That period may be extended by two (2) months taking into account the complexity and number of requests, the data subject then being informed of that extension and of the reasons for it within one month.

Exercising rights is in principle free of charge. However, where requests are manifestly unfounded or excessive, in particular because of their repetitive character, Vendora may charge a reasonable fee taking account of administrative costs, or refuse to act on the request, in accordance with Article 12 of the GDPR; the burden of demonstrating that the request is manifestly unfounded or excessive lies with Vendora.

Article 14 - Complaint to the CNIL

Independently of the option of contacting Vendora, any data subject who considers, after contacting Vendora, that the processing of their personal data infringes the applicable regulations has the right to lodge a complaint with a supervisory authority, in particular the French data protection authority (Commission nationale de l'informatique et des libertés, CNIL).

The CNIL may be contacted electronically through its website www.cnil.fr, or by post at: Commission nationale de l'informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.

Vendora nevertheless encourages data subjects to contact it first at contact@crozytraiteur.fr in order to seek, so far as possible, an amicable resolution of any difficulty.

Article 15 - Cookies and other trackers

The website www.crozytraiteur.fr may place and read cookies and other trackers on the user's device. A cookie is a small file that allows a browser to be recognised, certain information to be stored and browsing to be made easier. Placing and reading trackers is governed by Article 82 of the French Data Protection Act and by the CNIL's recommendations.

Cookies strictly necessary for the operation of the site: these trackers are essential to providing the service expressly requested by the user (session management, authentication and staying signed in to the client area, security, storing the cart or the content of the quote, respecting the user's cookie choice). They do not require the user's consent and rest on Vendora's legitimate interest in ensuring the proper operation and security of the site.

Internal traffic measurement cookies: Vendora places, without prior consent, two internal measurement cookies, which do not contain the user's IP address: "crozy_sid", a visit identifier, kept for the duration of the browsing session, and "crozy_src", which records the origin of the visit (source, campaign, landing page), kept for ninety (90) days. These cookies are used solely to measure traffic to the site and the origin of quote requests. The user may object to this processing at any time, in accordance with Article 21 of the GDPR, by written request sent to contact@crozytraiteur.fr.

Google Analytics audience measurement cookies and, where applicable, cookies linked to third-party services: these trackers are placed only after obtaining the user's prior, freely given, specific, informed and unambiguous consent, expressed through the cookie banner or management panel. The user can accept or refuse these trackers just as easily, and withdraw consent at any time.

The user may change their choices at any time through the cookie management module available on the site, or configure their browser to accept, block or delete cookies. Refusing cookies that are not strictly necessary has no effect on access to the essential features of the site, but blocking strictly necessary cookies may impair its operation.

The validity of cookie consent does not exceed six (6) months, after which consent is requested again. Cookies are not kept beyond thirteen (13) months and the information collected through them is not kept beyond twenty-five (25) months.

Article 16 - Commercial marketing and electronic communications

Vendora may send data subjects electronic communications about its catering services. As the clientele is professional (B2B), those communications may be sent on the basis of Vendora's legitimate interest, provided the approach relates to the profession of the person contacted, in accordance with the rules applicable to marketing aimed at professionals.

Where the recipient is already a client of Vendora, electronic marketing concerning products or services similar to those already supplied may be carried out without specific prior consent, in accordance with Article L. 34-5 of the French Postal and Electronic Communications Code.

In every case, each marketing communication states the sender's identity and provides a simple, free means of objecting to receiving further approaches (unsubscribe link). The data subject may also exercise their right to object at any time by writing to contact@crozytraiteur.fr, without that objection affecting the sending of transactional and operational communications needed to perform current contracts.

Article 17 - Protection of minors

The website www.crozytraiteur.fr and the services offered by Vendora are aimed exclusively at professionals and at adults acting in the course of their professional activity. They are neither intended for nor open to minors.

Vendora does not knowingly collect personal data relating to minors. Should data concerning a minor come to its attention, Vendora would delete it as soon as possible.

Anyone who believes that data relating to a minor has been collected is invited to inform Vendora at contact@crozytraiteur.fr so that it can be erased.

Article 18 - No automated individual decision-making or profiling

Vendora does not carry out any decision producing legal effects concerning data subjects, or similarly significantly affecting them, based solely on automated processing, including profiling, within the meaning of Article 22 of the GDPR.

Any automated processing carried out by Vendora, in particular for drawing up quotes, managing orders or preventing fraud, is carried out under the control and responsibility of the manager of the sole trader Vendora, who retains control over decisions affecting the contractual relationship.

Article 19 - Respective responsibilities and limitation of liability

Vendora is responsible for the processing it carries out and undertakes to comply with the applicable personal data protection regulations. As regards security, Vendora is subject to an obligation of means: it implements measures appropriate to the state of the art, the risk and the costs, without being able to guarantee absolute security against attacks not attributable to it.

The client, or the data subject acting on behalf of the client company, remains responsible for the accuracy, honesty and currency of the data it provides, and for compliance with its own obligations to inform and, where applicable, to obtain consent in respect of the third parties whose data it sends to Vendora (staff, on-site contacts, delivery recipients, guests).

To the extent permitted by law, Vendora may not be held liable for damage resulting from erroneous, incomplete or fraudulent data provided by the client, from a breach by the client of its own obligations, from unauthorised use of the data subject's login credentials, or from an event of force majeure within the meaning of Article 1218 of the French Civil Code.

These provisions may not limit or exclude the rights that data subjects derive from the applicable data protection regulations, nor Vendora's liability in the event of gross negligence or wilful misconduct, or in cases where the law prohibits it.

Article 20 - Changes to the Privacy Policy

Vendora reserves the right to amend or update this Policy at any time, in particular to take account of changes in the applicable regulations, case law, the recommendations of supervisory authorities or its own practices and processing.

The applicable version is the one in force and available on the website www.crozytraiteur.fr at the time of consultation or of collection of the data. The date of last update is stated at the top or the bottom of the document.

In the event of a substantial change affecting the processing or the rights of data subjects, Vendora will provide appropriate information, by any suitable means, before the change takes effect. Data subjects are advised to consult this Policy regularly.

Article 21 - Governing law, language and acceptance

This Policy is governed by French law and by the European Union regulations applicable to the protection of personal data, in particular the GDPR and the French Data Protection Act.

This Policy is drafted in French. In the event of translation, only the French version is authentic and prevails in the event of a difference of interpretation.

By browsing the website www.crozytraiteur.fr, requesting a quote, electronically signing a quote ("bon pour accord") or placing an order, the data subject acknowledges having read this Policy and accepts its terms, without prejudice to the rights they derive from the applicable regulations and which they may exercise at any time under the conditions set out in Articles 12 to 14.