PRIVACY POLICY – Screw express
1. Data Controller
This website is operated by Visserie Service, trading as Screw express .
Registered office: [Adresse complète à compléter]
Email: [email protected]
Visserie Service acts as the Data Controller within the meaning of the EU General Data Protection Regulation (EU) 2016/679 (“EU GDPR”) and the UK GDPR.
2. Scope of Application
This Privacy Policy applies to the processing of personal data of customers and users located in:
-
The European Union (EU GDPR)
-
The United Kingdom (UK GDPR)
Screw express processes personal data in accordance with applicable European and United Kingdom data protection laws.
3. Personal Data Collected
Screw express collects only personal data strictly necessary for its activities, including:
Identity and contact data
-
First and last name
-
Email address
-
Telephone number
-
Postal address (billing and delivery)
Order and transaction data
-
Products ordered
-
Order amounts
-
Order history
-
Customer service interactions
Payment data
Payments are processed exclusively by secure and certified payment providers.
Screw express does not store any banking or card details.
Technical and browsing data
-
IP address
-
Cookies
-
Device and browser information
-
Usage data and site interaction data
4. Purposes of Processing
Personal data is processed for the following purposes:
-
Managing orders and contractual relationships
-
Delivering products
-
Customer support and after-sales service
-
Processing payments
-
Issuing invoices and complying with accounting obligations
-
Responding to contact requests
-
Improving website functionality and user experience
-
Preventing fraud and ensuring website security
-
Sending marketing communications (only with explicit consent where required)
-
Complying with legal and regulatory obligations
5. Legal Basis for Processing
Processing of personal data is based on:
-
Performance of a contract (Article 6(1)(b) EU GDPR / UK GDPR)
-
Compliance with legal obligations (Article 6(1)(c))
-
Legitimate interests, including business management, fraud prevention, and service improvement (Article 6(1)(f))
-
User consent, where required (newsletter subscription, non-essential cookies)
Users may withdraw consent at any time without affecting the lawfulness of prior processing.
6. Data Retention Period
Personal data is retained only for as long as necessary:
-
For the duration of the contractual relationship
-
For legally required accounting and tax retention periods
-
Until withdrawal of consent for marketing communications
-
For the duration necessary to resolve disputes or enforce legal rights
Data is regularly reviewed and securely deleted when no longer required.
7. Recipients of Data
Personal data may be shared strictly when necessary with:
-
Secure payment providers
-
Transport and logistics providers
-
Website hosting provider
-
IT service providers and communication tools
-
Accounting or legal advisors where required
All service providers are contractually bound to ensure confidentiality and compliance with EU GDPR and UK GDPR.
8. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA) or the United Kingdom, appropriate safeguards are implemented in accordance with:
-
Standard Contractual Clauses (SCCs) approved by the European Commission
-
UK International Data Transfer Addendum
-
Adequacy decisions issued by the European Commission or the UK Government
The United Kingdom currently benefits from an EU adequacy decision.
9. Data Subject Rights
Under the EU GDPR and the UK GDPR, users have the following rights:
-
Right of access
-
Right to rectification
-
Right to erasure
-
Right to restriction of processing
-
Right to object
-
Right to data portability
-
Right to withdraw consent at any time
-
Right not to be subject to automated decision-making (where applicable)
Requests may be sent to:
[email protected]
A response will be provided within one month in accordance with applicable law.
10. Right to Lodge a Complaint
EU residents may lodge a complaint with their local data protection authority.
UK residents may lodge a complaint with the:
Information Commissioner’s Office (ICO)
Website: https://www.ico.org.uk
11. Cookies
Cookies are used to:
-
Ensure proper website functioning
-
Measure traffic and performance
-
Improve user experience
Non-essential cookies are placed only after obtaining user consent, in accordance with EU and UK cookie regulations.
Users may manage cookie preferences at any time via the cookie banner or browser settings.
12. Data Security
Screw express implements appropriate technical and organizational measures to ensure the confidentiality, integrity, and security of personal data, including:
-
Secure hosting infrastructure
-
Restricted access to authorized personnel
-
Encrypted payment processing
-
Regular security monitoring
13. UK Representative (if applicable)
Where required under Article 27 UK GDPR, Screw express will designate a UK Representative.
(If not applicable, you may remove this section.)
14. Policy Updates
This Privacy Policy may be updated at any time to reflect legal, regulatory, or operational changes.
The latest version is always available on this website