Last updated: 26 June 2025 · Applies to turcagrati.life
1. Data Controller
Turcagrati SARL, registered at 14 Rue de la République, 69002 Lyon, France (SIRET 89245673100014), is the data controller for personal data collected through this website and in the course of providing interior styling services. You may contact us at [email protected] or +33 4 78 42 19 56 regarding any privacy matter.
We process personal data in accordance with Regulation (EU) 2016/679 (GDPR), the French Data Protection Act (Loi Informatique et Libertés), and guidance from the CNIL (Commission Nationale de l'Informatique et des Libertés).
2. Personal Data We Collect
Through contact forms, email and telephone we may collect your name, email address, phone number, postal address, property details and message content. When you become a client we additionally process billing information, project photographs (with consent), correspondence and payment records necessary to fulfil our contract.
When you browse our website, we may collect technical data such as IP address, browser type, pages viewed and referral source. Non-essential analytics cookies are placed only after your consent via the cookie banner; see our Cookie Policy for details.
3. Purposes and Legal Bases
We use your data to respond to enquiries, deliver styling services, issue invoices, comply with legal obligations and, where permitted, send service-related updates. Contract performance (Article 6(1)(b) GDPR) covers client data needed to provide agreed services. Legitimate interest (Article 6(1)(f)) applies to limited website security logging and B2B relationship management, balanced against your rights.
Marketing communications are sent only with your consent (Article 6(1)(a)) or under applicable soft-opt-in rules where you are an existing client and may opt out at any time. Legal obligation (Article 6(1)(c)) covers tax and accounting retention requirements under French law.
4. Recipients and Transfers
Data may be shared with subprocessors who assist us under contract: hosting providers, email services, accounting software and payment processors. All subprocessors are bound by data processing agreements and located within the European Economic Area unless adequate safeguards are in place.
We do not sell personal data. Disclosure to public authorities occurs only when required by law. If a transfer outside the EEA becomes necessary, we implement Standard Contractual Clauses or another CNIL-approved mechanism and inform you where required.
5. Retention Periods
Enquiry data is retained for up to 24 months unless a business relationship begins. Client project files and invoices are kept for 10 years after the last transaction to meet French commercial and tax obligations. Cookie consent records are stored locally in your browser and on our systems for up to 13 months where applicable.
When retention periods expire, data is securely deleted or anonymised. Backups may persist for a limited technical window before automatic purging.
6. Your Rights
Under GDPR you have the right of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interest or direct marketing. Where processing relies on consent, you may withdraw consent at any time without affecting prior lawful processing.
To exercise your rights, contact [email protected] with proof of identity. We respond within one month, extendable by two months for complex requests. You may lodge a complaint with the CNIL at www.cnil.fr if you believe your rights have been infringed.
7. Security Measures
We implement appropriate technical and organisational measures including access controls, encrypted connections where supported, staff confidentiality obligations and supplier due diligence. No method of transmission over the internet is completely secure; we encourage you not to send sensitive documents via unencrypted email.
In the event of a personal data breach likely to affect your rights, we will notify the CNIL within 72 hours where required and inform affected individuals without undue delay when the breach poses a high risk.
8. Minors and Automated Decisions
Our services are directed at adults. We do not knowingly collect data from persons under 16 without parental consent. We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.
9. Changes to This Policy
We may update this Privacy Policy to reflect legal or operational changes. The revision date at the top will be amended accordingly. Material changes will be highlighted on this page or communicated to active clients where appropriate.