Privacy Policy
Last updated: March 2026
Introduction
Protecting your personal data matters to us. This privacy policy explains what data we collect, why we collect it, and how we use it, in compliance with the General Data Protection Regulation (GDPR).
Data Controller
The data controller is the publisher of acide-urique-goutte.com.
Contact: contact form
Data We Collect
- When you make a purchase: name, email address, billing address. This data is necessary to fulfill your order.
- When you create an account: email address and password (encrypted).
- When you browse: essential technical cookies required for the website to function. We do not use advertising or tracking cookies.
How We Use Your Data
- Processing orders and delivering digital products
- Managing user accounts
- Order-related communications (confirmation, follow-up)
- Improving the website and user experience
Legal Basis
Processing is based on contract performance (for purchases) and your consent (for newsletters, if applicable).
Data Sharing
Your data is never sold to third parties. It is shared only with:
- Stripe: for secure payment processing. Stripe is PCI DSS Level 1 certified.
- o2switch: our hosting provider, for website data storage.
Data Retention
Order-related data is retained for the legally required period (10 years for accounting records under French law). Account data is kept as long as the account is active. You may request account deletion at any time.
Your Rights
Under the GDPR, you have the following rights:
- Right to access your data
- Right to rectification
- Right to erasure (“right to be forgotten”)
- Right to data portability
- Right to object to processing
- Right to withdraw consent at any time
To exercise these rights, contact us at contact form.
Cookies
This website uses only essential technical cookies (WordPress session, WooCommerce cart). No advertising or third-party tracking cookies are placed.
Security
We implement appropriate technical and organizational measures to protect your data against unauthorized access, modification, disclosure, or destruction. Communications are encrypted via SSL/TLS.
Complaints
If you believe your rights have not been respected, you may file a complaint with the French data protection authority (CNIL) at www.cnil.fr, or with your local supervisory authority.