EN-2026.08.14-1 · Effective 14 August 2026
Privacy Policy
How order, measurement, support and security data is used and shared.
1. Controller and scope
The controller is Ibrahim Danso, trading as Danso Atelier, at 4 rue Pierre Ginier, 75018 Paris, France. Contact: contact@dansoatelier.com or +33758601643.
This policy covers information processed through dansoatelier.com, the central order and payment hub, authorised ordering storefronts that send an order to this merchant, customer support, invoicing, production and delivery. The checkout must identify the legal seller; this policy does not conceal the storefront through which a customer placed the order.
2. Data, purposes and legal bases
| Information | Purpose | Legal basis |
|---|---|---|
| Name, email, telephone, billing and delivery address | Quote, order, delivery, support and fraud review | Contract; legitimate interests in protecting orders; legal obligations |
| Body measurements, fit, cloth, finish and alteration notes | Make and adjust the commissioned garment | Performance of contract |
| Product, quantity, price, currency, order/invoice reference and timestamps | Order administration, accounting, customer evidence and dispute handling | Contract; legal obligation; legitimate interests |
| Payment provider reference, payment status, refund and dispute events | Confirm and reconcile payment and respond to disputes | Contract; legal obligation; legitimate interests |
| Carrier, tracking number, dispatch and delivery status | Fulfilment and proof of delivery | Contract; legitimate interests |
| IP address, signed-request identifiers and security logs | Session security, abuse prevention, audit and incident response | Legitimate interests; legal obligations where applicable |
| Messages, complaints and after-sales evidence | Customer care, guarantees, claims and mediation | Contract; legal obligation; legitimate interests |
Please do not send medical information or card details in measurement notes or support messages. Where a limited detail is genuinely needed for fit or accessibility, provide only what is necessary.
3. Where information comes from
Information comes directly from the customer; from an authorised WooCommerce or JTL storefront used to place the order; from Stripe or PayPal when offered for payment status and fraud signals; and from the carrier for tracking and delivery. The central catalogue validates product identifiers, quantities and exact prices rather than selecting an arbitrary amount.
4. Recipients
Access is limited to the seller and service providers that need the information for their role: the hosting provider; Stripe or PayPal when offered; the transactional email provider; the selected carrier; and professional advisers or public authorities where legally required. Data is not sold, rented or disclosed for third-party advertising.
5. Payment information
Payment credentials are entered on a provider-hosted page. This website stores order totals and provider references, not the full card number or card security code. Stripe and PayPal process payment data under their own privacy notices and regulatory duties.
6. International transfers
Some providers may process information outside the European Economic Area. Where required, the provider and controller rely on an adequacy decision, European Commission Standard Contractual Clauses or another lawful safeguard. Provider documentation is available from Stripe Privacy and PayPal Privacy.
7. Retention
Retention depends on purpose and statutory duties. The working schedule—including the distinction between an active record and legally restricted archive—is published in Data Rights & Retention. We do not keep information simply because storage is available.
8. Your rights
Subject to legal conditions, you can request access, correction, erasure, restriction, objection and portability, and can give instructions concerning data after death. Send a request to contact@dansoatelier.com. Identity evidence is requested only where reasonably necessary. We normally respond within one month; a lawful extension will be explained.
You can complain to the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.
9. Security
Controls include HTTPS in production, restricted administrator access, scoped session cookies, signed requests between authorised storefronts and the hub, protected stored connector secrets, provider-hosted payment entry, verified provider notifications and protected storage directories. No system can promise absolute security; suspected incidents are investigated and notified where law requires.
10. Automated checks and marketing
Payment providers may use automated fraud and authentication tools under their own notices. The seller can manually review an unusual order. This website does not use customer order data for third-party advertising and does not send promotional email merely because a customer paid. Transactional messages—confirmation, invoice, production, shipment and support—are sent to perform the order.
11. Changes
A new version and effective date will be published when this policy materially changes. A change does not retrospectively alter the contract or legal basis for an earlier order.