Privacy Policy

B&K LUMITEC is attached to the protection privacy and to personal data from natural persons.

B&K LUMITEC complies with the European General Data Protection Regulation (« GDPR ») and the French law called « Information Technology and Civil Liberties ».

B&K LUMITEC complies in particular with the information and transparency requirements imposed on it by these legislations, by making available, in particular, on its internet Website (http://www.bklumitec.com), this present section accessible from all pages of the Website.

This section aims to:

  • inform about personal data processing that are being carried out for the management of the commercial activities form B&K LUMITEC and that concern:
    • natural persons who are customers from B&K LUMITEC or who are likely to become so (« prospects »),
    • natural persons who are collaborators of the customers and of the prospects of B&K LUMITEC (the word « collaborator » means here managers, employees, trainees, temporary staff and all persons under the direct authority of a customer or a prospect from B&K LUMITEC),
    • and natural persons who visit the Website,

 

  • and to inform these persons about their rights with regard to the processing of their personal data.

 

 

INTERACTIVE MAP OF THE SECTION :

1. Who is the data controller?

2. What is a personal data?

3. How does B&K LUMITEC collect the personal data it processes?

4. What are the collected personal data, for which purposes and on which legal basis?

5. Who are the recipients of the collected personal data?

6. Are the collected personal data transfered to states outside the European Economic Area?

7. What is the retention period of the collected personal data?

8. What security for the collected personal data?

9. The rights of the data subjects with regard to the processing of their personal data

10. THE DATA SUBJECT’S remedies RIGHTs

11. Your contact for all your questions about the protection of your personal data

 

 

1. WHO IS THE DATA CONTROLLER?

The data controller is the company B&K LUMITEC (Simplified joint stock company with a registered capital of 102 000 Euros - Registered in the Trade and Companies Register of STRASBOURG under the number 391 240 504).

Contact details of the data controller:
Head office: 2, rue Alfred Kastler, F-67850 HERRLISHEIM
Phone: +33 (0) 3 88 96 80 90 (not overcharged number)
Fax: +33 (0) 3 88 96 48 46
Email: info@bklumitec.com

 

2. WHAT IS A PERSONAL DATA?

A personal data is any information relating to an identified or identifiable natural person.

A natural person is considered as identifiable where she can be identified, directly or indirectly, in particular by reference to:

  • an identifier such as a name, an identification number (e.g., a customer number, a smartphone number), location data, an online identifier (e.g., an IP-address),
  • or to one or more factors specific to her physical, physiological, genetic, mental, economic, cultural or social identity (e.g., her buying habits).

 

3. HOW DOES B&K LUMITEC COLLECT THE PERSONAL DATA IT PROCESSES?

3.1 B&K LUMITEC collects only the personal data which are strictly necessary for the purposes for which the data are processed (data minimisation rule).

3.2 The personal data, processed by B&K LUMITEC, are collected by B&K LUMITEC directly from the data subject to whom they are related to (called “the data subject”).

It is:

  • the data which the data subject knowingly provides to B&K LUMITEC.

E.g., by contacting B&K LUMITEC by phone, by filling out a contact-form or by interacting with B&K LUMITEC on its Website,

  • and the data which B&K LUMITEC collects, and which are sent to it automatically by the browser that the data subject uses to connect to its Website.

E.g., an IP-address, the type of browser used by the data subject.

3.3 Where personal data are collected by means of a form, the failure to reply to a mandatory field (field marked with a *) prevents B&K LUMITEC from responding to the request sent to it through this form (e.g., contact request, account creation request, order).

 

4. WHAT ARE THE COLLECTED PERSONAL DATA, FOR WHICH PURPOSES AND ON WHICH LEGAL BASIS?

The answers to these questions are provided in the following table which contains:

  • a description of the situations in which personal data are collected,
  • and for each of these situations:
    • the categories of personal data collected,
    • the purposes of the processing that are carried out on the personal data collected (= which use(s) are made of the data and for which purpose(s))
    • the legal basis of these processing (= the legal basis that allows B&K LUMITEC to process the personal data).

Situations in which personal data are collected

Categories of personal data collected

Purposes of the processing carried out on the personal data collected

Legal basis of the processing carried out on the personal data collected

 

By connecting and browsing on our Website

 

Technical data connexion:

  • the type of browser the version of the browser used for the connection by the data subject
  • the operating system used by the data subject
  • the originating URL (= from the previous web page from which you connect to our Website)
  • host name of the connecting equipment (your computer, smartphone, etc.) to our Website
  • time of the connection request
  • IP-address.

These data are not cross-checked with other data sources.

 

The managing, the securing and the improving the Website, as well as securing the tools and the information system of B&K LUMITEC

 

 

 

 

 

 

 

 

 

 

The achievement of a legitimate interest pursued by B&K LUMITEC (article 6 (1) (f) GPDR) – namely: to improve and to ensure the stability, functionality and security of its Website, as well as the security of its tools and its information system.

 

The creation of a customer account

 

  • last name and first name
  • postal addresses (places of establishment, of delivery, of billing)
  • email address
  • phone number (landline and mobile)
  • fax number
  • For the french customers: the data contained on the extract of the Commercial and Companies Register (“extrait Kbis“) or on the extract of the registration in the Trades Register (“Répertoire des métiers”)
  • For the customers established in the EU: intracommunity VAT number
  • For the customers established in Switzerland: tax number
  • a password (to be created by the customer when requesting the opening of the customer account)

 

  • Management of the customer account:
  • to process the request for opening a customer account
  • to manage the customer account (included its deletion)
  • to allow the account holder (and its collaborators authorised by him) to access and to use it
  • to manage amicably the complaints related to the customer account

 

The performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (article 6 (1) (b) GDPR).

 

  • Management of the disputes related to the customer account in the context of pre-litigation and litigation

 

The achievement of a legitimate interest pursued by B&K LUMITEC (article 6 (1) (f) GPDR) – namely: to be able to establish, exercise or defend its rights in court.

 

Requests for information (Requests for information that is not freely available on the Website require the prior creation of a customer account)

 

  • The email adress communicated at the time of the request for opening a customer account
  • The password created where the creation of the customer account

 

The processing of these requests in order to give them a response

 

 

The performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (article 6 (1) (b) GDPR).

 

The placement of an order
(The placement of an order requires the prior creation of a customer account)

 

  • last name and first name
  • postal addresses (places of establishment, of delivery, of invoicing)
  • email address
  • phone number (landline and mobile)
  • fax number
  • customer number
  • transaction data (number, date, amount, periodicity and details of the order (types and quantities of products ordered) and of the invoice (included its due date)
  • conditions and methods of payment
  • purchase history
  • bank details (identity of the account holder, account number, IBAN, SWIFT Code)
  • cheque number in case of a payment by cheque

 

 

 

 

 

 

 

 

 

 

 

 

 

  • Management of the contracts:

- to process, to manage, to perform to follow up (included the delivery of the products and the receipt of their payment) the order
- to manage after-sales service, complaints and all warranty issues related to the order
- to process and manage all contacts from the customer who placed the order and / or her / his collaborators and which are dealing with the order
- to manage amicably the complaints related to the order

 

The performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (article 6 (1) (b) GDPR).

 

  • Management of the disputes related to the order in the context of pre-litigation and litigation

 

The achievement of a legitimate interest pursued by B&K LUMITEC (article 6 (1) (f) GPDR) – namely: to be able to establish, exercise or defend its rights in court.

 

  • Carrying out studies and analyses of sales statistics for prospecting purposes

 

 

 

The achievement of a legitimate interest pursued by B&K LUMITEC (article 6 (1) (f) GPDR) – namely: to gain a better knowledge and understanding of the needs and expectations of its customers in order to better respond to them.

 

  • The compliance by B&K LUMITEC with its accounting and tax obligations

 

The compliance with a legal obligation to which B&K LUMITEC is subject (article 6 (1) (c) GDPR).

 

The payment of an order if the customer chooses to pay it by bank card

 

  • The data related to the bank card: identity of the bank card, bank card number, its expiry date and its visual cryptogram

 

  • The management and receipt of the payment for the order for which the bank card data have been provided

 

The performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (article 6 (1) (b) GDPR).

 

  • The data related to the bank card: identity of the bank card, bank card number and its expiry date

 

  • Management of the disputes related to the payment transaction in the context of pre-litigation and litigation

 

 

The achievement of a legitimate interest pursued by B&K LUMITEC (article 6 (1) (f) GPDR) – namely: to be able to establish, exercise or defend its rights in court.

 

The request for subscription to the newsletter from B&K LUMITEC

 

  • email address

 

  • The management of the subscription to the newsletter:
  • to process the request for subscription
  • to manage the newsletter service (included the unsubscription)
  • to send the newsletters

 

The consent given by the data subject for this specific purpose (article 6 (1) (a) GPDR).

 

 

 

  • The management of the consent given by the data subject:
  • to keep evidence of the consent given by the data subject,
  • to manage the withdrawal of the consent.

 

The compliance with a legal obligation to which B&K LUMITEC is subject (article 6 (1) (c) GDPR).

 

The communication of specific directives concerning the fate of her / his personal data after her / his death

 

  • last name and first name
  • postal address
  • email address
  • the specific directives concerning the retention, the erasure and the transmission of her / his personal data after her / his death

 

  • The recording and the retention of the specific directives communicated by the data subject

 

The consent given by the data subject for this specific purpose (article 6 (1) (a) GPDR).

 

  • The management of the consent given by the data subject:
  • to keep evidence of the consent given by the data subject,
  • to manage the withdrawal of the consent.

 

The compliance with a legal obligation to which B&K LUMITEC is subject (article 6 (1) (c) GDPR).

 

5. WHO ARE THE RECIPIENTS OF THE COLLECTED PERSONAL DATA?

To fulfil the purposes for which the personal data have been collected, B&K LUMITEC transfers these data to different people.

The following table informs about the categories of persons who, for the fulfilment of one or more of these purposes, receive communication of personal data.

Purposes of the processing carried out on the personal data collected

Categories of recipients of the personal data communicated

 

The securing of the tools and the information system of B&K LUMITEC and the operation and improvement of the Website

 

The IT service provider of B&K LUMITEC

 

The management of customer’s accounts

 

- B&K LUMITEC’s sales department and accounting department

 

The management of the disputes related to the customer account in the context of pre-litigation and litigation

 

- Lawyers
- Experts
- Court officers, judicial officers
- Médiators, conciliators, arbitrators, and courts
- Insurers
- B&K LUMITEC’s sales department and accounting department

 

The processing of information requests

 

- B&K LUMITEC’s sales department

 

The management of the contracts

 

- B&K LUMITEC’s sales department, accounting department and shipping department

 

The transport service providers used by B&K LUMITEC to deliver the products

  • Categories of data communicated: postal address, last name and first name, phone number (landline and mobile).

 

The banking institutions used by B&K LUMITEC in connection with the payment of orders

 

The management and receipt of the payment for the order for which the bank card data have been provided

 

 

- B&K LUMITEC’s sales department and accounting department

- The banking institutions used by B&K LUMITEC in connection with the payment of orders

 

The management of the disputes related to the order (included related to the payment transaction by bank card) in the context of pre-litigation and litigation

 

- Lawyers
- Experts
- Court officers, judicial officers
- Mediators, conciliators, arbitrators, and courts
- Insurers
- B&K LUMITEC’s sales department and accounting department

 

Carrying out studies and analyses of sales statistics for prospecting purposes

 

- B&K LUMITEC’s sales department

 

The compliance by B&K LUMITEC with its accounting and tax obligations

 

- B&K LUMITEC’s accounting department
- the accounting firm of B&K LUMITEC
- The tax administration

 

The management of the Newsletter 

 

- The IT service provider of B&K LUMITEC
- The newsletter service provider
- B&K LUMITEC’s sales department

 

The management of consents given by the data subject to certain specific processing of his/her personal data

 

- B&K LUMITEC’s sales department
- The IT service provider of B&K LUMITEC

 

The recording and the retention of specific directives communicated by the data subject concerning the fate of her / his personal data after her / his death

 

- B&K LUMITEC’s sales department

 

6. ARE THE COLLECTED PERSONAL DATA TRANSFERED TO STATES OUTSIDE THE EUROPEAN ECONOMIC AREA

The anwser is no.

The personal data collected is stored and processed exclusively on the territory of a Member State of the European Economic Area.

For the implementation of the personal data processing described in this section, B&K LUMITEC does not use any processor established outside the European Economic Area.

 

7. WHAT IS THE RETENTION PERIOD OF THE COLLECTED PERSONAL DATA

B&K LUMITEC keeps personal data in a form which permits identification of the data subjects only for as long as is strictly necessary for the purposes for which the data have been collected (storage limitation rule).

The retention period of the personal data therefore varies according to the aim (= the purpose) that is being pursued by B&K LUMITEC with these data and the applicable legal provisions which may impose a particular retention period.

In the event that the same personal data is required for several different purposes, this data will be kept by B&K LUMITEC until all the purposes pursued with this data have been achieved.

The following table informs, purpose for purpose:

  • about the retention period of these personal data,

or

  • in cases where it is not possible to indicate this retention period, on the criteria used by B&K LUMITEC to determine it.

 

Purposes of the processing carried out on the personal data collected

 

Retention period of the personal data
/ OR
Criteria used to determine this period

 

The securing of the tools and the information system of B&K LUMITEC and the operation and improvement of the Website

 

14 days after the end of each connection by the data subject to the Website

 

The processing of information requests

 

 

Retention for a period of 2 years from the last contact initiated by the customer with B&K LUMITEC.

 

The management of customer’s accounts

 

 

 

Retention:
- until the customer account is deleted,
- or, in the absence of deletion, for a period of 2 years from the last contact initiated by the customer with B&K LUMITEC.

This period is increased by the limitation period provided by the applicable law (E.g., 5 years for French law).
Legal basis for the retention: the achievement of a legitimate interest pursued by B&K LUMITEC (article 6 (1) (f) GPDR) – namely: to be able to establish, exercise or defend its rights in court.

 

The management of the disputes related to the customer account in the context of pre-litigation and litigation

 

The management of the contracts

 

Retention for the duration of the contractual relationship.

This period is increased:

- by the limitation period provided for by the applicable law (e.g., 5 years for French law).
Legal basis for the retention: the achievement of a legitimate interest pursued by B&K LUMITEC (article 6 (1) (f) GPDR) – namely: to be able to establish, exercise or defend its rights in court.

- and by the retention periods required by the applicable legal and regulatory provisions (e.g., 10 years for invoicing and accounting data).
Legal basis for the retention: the compliance with a legal obligation to which B&K LUMITEC is subject (article 6 (1) (c) GDPR).

 

The management of the disputes related to the order in the context of pre-litigation and litigation

 

The compliance by B&K LUMITEC with its accounting and tax obligations

Carrying out studies and analyses of sales statistics for prospecting purposes

 

Retention:
- for a period of 3 years from the last contact initiated by the customer with B&K LUMITEC,
- or until the data subject exercises his or her right to object.

 

The management and receipt of the payment for the order for which the bank card data have been provided

 

Retention of the data (identity of the bank card, bank card number, its expiry date, and its visual cryptogram) until the effective and complete payment of the transaction for which the data was communicated.

 

The management of the disputes related to a payment transaction by bank card in the context of pre-litigation and litigation

 

 

Retention of the data (identity of the bank card, bank card number and its expiry date) for a period of:
- 13 months from the date of debit,
- or 15 months from the date of debit if the bank card used is a deferred debit card.

 

The management of the Newsletter 

 

 

Retention:
- until the data subject withdraws his or her consent (unsubscribe request),
- or, failing that, for a period of 3 years from the last contact initiated by the data subject.

 

The management of consents given by the data subject to certain specific processing of his/her personal data

 

Retention until the data subject withdraws his or her consent.

This period is increased by the limitation periods provided for by the applicable law.
Legal basis for the retention: the achievement of a legitimate interest pursued by B&K LUMITEC (article 6 (1) (f) GPDR) – namely: to be able to establish, exercise or defend its rights in court.

 

The recording and the retention of specific directives communicated by the data subject concerning the fate of her / his personal data after her / his death

 

Retention until the data subject withdraws his or her consent.

 

8. WHAT SECURITY FOR THE COLLECTED PERSONAL DATA?

B&K LUMITEC implements technical and organisational measures which, given the current state of knowledge and risks, are reasonably appropriate to ensure the security of the personal data collected.

B&K LUMITEC’s Website uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or requests you send us. You can recognise an encrypted connection by the fact that the browser address line changes from "http://" to "https://" and by the closed lock symbol. If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

 

9. THE RIGHTS OF THE DATA SUBJECTS WITH REGARD TO THE PROCESSING OF THEIR PERSONAL DATA

9.1 THE DATA SUBJECT’S RIGHT TO OBJECT

The right to object to the processing of personal data is a right that allows the data subject to object, at any time, to the use of his/her personal data for a specific purpose that the processing, to which he/she objects, is intended to achieve.

Cases in which the data subject has a right to object

The conditions to be complied with by the data subject

RESTRICTIONS

 

CASE N° 1: the legal basis for the processing is a legitimate interest pursued by B&K LUMITEC (except in the case of processing for direct marketing purposes).

The list of the processing, which have this legal basis, can be found in 4. of this section: see the column entitled « Legal basis of the processing carried out on the personal data collected ».

 

When exercising his or her right to object, the data subject must indicate to B&K LUMITEC which is
or are the reason(s) relating to his/her particular situation for which he/she exercises his/her right to object.

 

 

B&K LUMITEC may override the exercise of a right to object and continue to process the personal data if B&K LUMITEC demonstrate:
- either there is compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject,
- or the processing is necessary for the establishment, exercise, or defence of legal claims.

 

CASE N° 2: the processing has direct marketing purpose.

The list of the processing, which have this purpose, can be found in 4. of this section: see the column entitled « Purposes of the processing carried out on the personal data collected ».

 

None: the data subject does not have to give reasons for exercising the right to object.

 

None

 

9.2 THE OTHER DATA SUBJECT’S RIGHTS

LIST OF THE OTHER RIGHTS

What does it mean?

RESTRICTIONS

 

The right to be informed

 

This right allows you to be informed about the processing of your personal data by B&K LUMITEC and about your rights in relation to these processing.
The aim of this section is to provide this information.

 

None

 

The right of access to his / her data

 

This right includes:

- the right to know whether your personal data are processed by B&K LUMITEC,

- and, if so, the right to obtain a copy of your processed personal data and information about their processing.

 

A fee not exceeding the cost of the copy may be charged.

 

The right to rectification of his / her data

 

This right allows you to request the rectification of inaccurate or incomplete information concerning you.

 

None

 

The right to erasure of his / her data (« right to be forgotten »)

 

 

This right allows you to obtain from B&K LUMITEC the erasure, without undue delay, of your personal data.

 

1st restriction: The right to erasure does not apply in the following 2 cases:

  • the processing of the personal data is necessary for compliance with a legal obligation to which B&K LUMITEC is subject,
  • the processing of the personal data is necessary for the establishment, exercise, or defence of legal claims.

2nd restriction: In order to exercise his or her right to erasure, the data subject must provide a reason from a (limited) list of reasons.
E.g., his or her personal data are no longer necessary for the purpose(s) for which they were collected.
To view the full list of reasons, click

 

 

The right to data portability

 

This right allows you to receive, in a structured, commonly used and machine-readable format (computer, smartphone, etc.), the personal data concerning you that you have provided to B&K LUMITEC.

You can then reuse them and/or pass them on to another controller.

You can also ask B&K LUMITEC to transfer your personal data directly to another, where technically feasible.

 

The right to data portability applies only to personal data whose processing is carried out by automated means and which is based:
- either on the basis of the consent of the data subject,
- the existence of a contract between the data subject and B&K LUMITEC.

The list of the processing operations which have one of these two legal basis can be found in 4. of this section: see the column entitled « Legal basis of the processing carried out on the personal data collected ».

The exercise of the right to portability must not infringe the rights and freedoms of third parties.

 

The right to restriction of the processing of his / her data

 

Where this right is exercised, B&K LUMITEC:

  • keeps the personal data,
  • but may not further process or use it (except in the 2 cases indicated in the "Restriction" column).

The restriction of a processing is a temporary measure. B&K LUMITEC informs the data subject before the restriction of processing is lifted.

 

1st restriction: In order to exercise his or her right to restriction, the data subject must justify a reason from a (restrictive) list of reasons.
E.g., contest the accuracy of his or her processed personal data. In this case, the limitation will last for a period enabling B&K LUMITEC to verify the accuracy of the personal data.
To view the full list of reasons, click

2nd Restriction: Where this right is exercised, B&K LUMITEC may still make other uses of the personal data (in addition to storing them) in the following 2 cases:

  • B&K LUMITEC has obtained the consent of the data subject to make that other use (=processing),
  • This other use is necessary:

- for the establishment, exercise, or defence of legal claims,
- or for the protection of the rights of another natural or legal person,
- ou for reasons of important public interest of the Union or of a Member State.

 

The right to withdraw at any time his or her consent to the processing of his / her personal data

 

 

This right allows you to obtain at any time that B&K LUMITEC ceases the processing for which you have withdrawn your consent.

In the particular case of newsletter subscription, the consent can be withdrawn:

  • by clicking on the "Unsubscribe" link contained in each Newsletter sent,
  • or in accordance with the terms and conditions set out in 8.3 of this section.

The withdrawal of consent:
- is valid for the future,
- and shall not affect the lawfulness of processing based on consent before its withdrawal.

 

This right applies to processing operations whose legal basis is the consent of the data subject.

The list of these processing operations can be found in 4. of this section: see the column entitled « Legal basis of the processing carried out on the personal data collected ».

 

The right to set specific directives relating to the retention, deletion and disclosure of personal data after his/her death

 

 

This right allows you to set, in the form of general and/or specific instructions, how you want your rights to be exercised after your death.

The general directives concern all your personal data. They can be registered with a trusted digital third party certified by the CNIL.

The specific directives concern (only) the processing of your personal data that they mention. They must be communicated to the relevant data controllers for registration.
You can therefore define and communicate to B&K LUMITEC specific directives concerning the processing of your personal data by B&K LUMITEC. In this case, B&K LUMITEC will record and store your instructions.
You can change or revoke your specific directives at any time by contacting B&K LUMITEC (see 8.3 of this section).

 

None

 

9.3 HOW CAN THE DATA SUBJECT EXERCISE HER / HIS RIGHTS AGAINST B&K LUMITEC

Data subjects may, at any time and provided they can prove their identity by any means, exercise their rights by sending their request to B&K LUMITEC:

  • either by email at info@bklumitec.com,
  • or by post to the following address: B&K LUMITEC - 2, rue Alfred Kastler – F-67850 HERRLISHEIM.

Where B&K LUMITEC has reasonable doubts concerning the identity of the natural person making a request to exercise his or her rights, B&K LUMITEC may request the provision of additional information, including, where necessary, a photocopy of an identity document bearing the holder's signature.

 

10. THE DATA SUBJECT’S REMEDIES RIGHTS

If you believe that the processing of your personal data constitutes a breach of applicable legal rules (GDPR, « Information Technology and Civil Liberties » Law), you have:

  • The right to lodge a complaint with a supervisory authority

The competent supervisory authority in France is the CNIL (« Commission nationale de l'informatique et des libertés »). For more information, see for example the section « Adresser une réclamation (plainte) à la CNIL : à quelles conditions et comment ? » available on the CNIL website (https://www.cnil.fr/fr/cnil-direct/question/844).

  • The right to bring an action before a Court

 

11. YOUR CONTACT FOR ALL YOUR QUESTIONS ABOUT THE PROTECTION OF YOUR PERSONAL DATA

For any questions you may have concerning the collection and use of your personal data or your rights regarding the processing of your personal data, you can contact B&K LUMITEC:

  • either by email at info@bklumitec.com,
  • or by post to the following address: B&K LUMITEC - 2, rue Alfred Kastler – F-67850 HERRLISHEIM.


(update date: 18.01.2022)