Last updated 14 August 2026
Privacy Policy
Controller
Ibrahim Danso, individual entrepreneur, 4 rue Pierre Ginier, 75018 Paris, France — SIRET 993 546 571 00015. Contact: contact@dansoatelier.com.
Data we process
| Category | Purpose | Legal basis | Indicative retention |
|---|---|---|---|
| Identity and contact: name, email, phone, address | Order, delivery and support | Performance of contract | 3 years after last contact, subject to legal records |
| Body measurements | Making, alterations and repeat orders | Performance of contract | 3 years after the last order |
| Order history and cloth preferences | Customer service and accounting | Contract and legal obligation | Accounting records: 10 years |
| Payment data | Card payment | Performance of contract | Processed by Stripe; card data is not stored by the seller |
| IP and security logs | Security and fraud prevention | Legitimate interests | Up to 13 months where applicable |
Recipients and processors
Information is available only to authorised persons and service providers to the extent needed for their work: Stripe for payment and fraud prevention; the production hosting provider; the selected carrier; and any configured transactional email provider. Data is not sold or disclosed for third-party advertising.
International transfers
Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, European Commission Standard Contractual Clauses, or another lawful safeguard described by the provider.
Your rights
Subject to the applicable conditions, you may request access, correction, erasure, restriction, objection and portability, and give instructions for your data after death. Email contact@dansoatelier.com. We may request proof of identity where necessary and will respond within one month, subject to lawful extensions. You may complain to the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr.
Security
Production deployment must use HTTPS, restricted administrative access, signed Stripe webhooks, least-privilege access and regular backups. Local development records must never be populated with real customer card data.