Privacy Policy
Last updated: March 2026 · GDPR & French Data Protection Law compliant
1. Data Controller
Samira Fawaz / ORIVIAA
2 rue du Château, 95360 Montmagny, France
SIRET : 992 546 812 00015
Email : hello@oriviaa.com
2. Data Collected
We collect the following data, depending on interactions with the website:
Via contact and quote forms:
- First name, last name
- Professional or personal email address
- Phone number (if provided)
- Company name and sector (for B2B clients)
- Free message, estimated budget, needs
Via website navigation (with consent):
- IP address (anonymized)
- Pages visited, session duration, interactions
- Browser type, operating system, screen resolution
- Traffic source (referrer, campaign)
3. Purposes and Legal Basis of Processing
| Purpose | Legal basis |
|---|---|
| Processing your contact and quote requests | Pre-contractual measures |
| Client relationship management and invoicing | Contract performance |
| Audience measurement and site improvement (Google Analytics) | Consent |
| Commercial email prospecting | Consent (B2C) / Legitimate interest (B2B) |
| Compliance with accounting and tax obligations | Legal obligation |
4. Data Retention Period
- Contact and quote data : 3 years from the last contact or end of the commercial relationship
- Client data (invoicing, contracts) : 10 years in accordance with French accounting obligations
- Navigation data (analytics) : 13 months maximum (CNIL recommendation)
- Commercial prospecting data : 3 years from collection or last contact
5. Sub-processors and Data Recipients
ORIVIAA uses the following sub-processors, who process personal data on our behalf:
Vercel Inc.
Role : Website hosting
Location : États-Unis / USA
Transfer guarantee : EU Standard Contractual Clauses (SCC)
Google LLC (Google Analytics)
Role : Audience measurement (with your consent)
Location : États-Unis / USA
Transfer guarantee : Standard Contractual Clauses + EU-US DPF
6. Data Transfers Outside the European Union
Some sub-processors (Vercel, Google) are established in the United States. These transfers are governed by the following legal mechanisms:
- Standard Contractual Clauses (SCC) adopted by the European Commission, guaranteeing a level of protection equivalent to that of the EU
- The EU-US Data Privacy Framework (DPF), in force since July 2023, for certified entities
7. Data Security
ORIVIAA implements appropriate technical and organizational measures to protect your data against unauthorized access, loss, destruction or alteration. These measures include: encrypted connections (HTTPS/TLS), restricted access to data by authentication, use of platforms meeting industry security standards. In the event of a data breach likely to create a risk to your rights and freedoms, ORIVIAA undertakes to notify the CNIL within 72 hours and the data subjects as soon as possible.
8. Protection of Minors
The oriviaa.com website is intended for an adult and professional audience. ORIVIAA does not knowingly collect personal data about persons under the age of 15. If you are the parent or guardian of a minor whose data you believe has been collected without your consent, please contact us at hello@oriviaa.com so that we can delete this data.
9. Email Marketing — Commercial Prospecting
ORIVIAA may send commercial communications by email under the following conditions:
- Individual clients (B2C) : only with your prior, express and free consent. You can unsubscribe at any time via the link in each email.
- Professional clients (B2B) : on the basis of ORIVIAA's legitimate interest, for offers related to already subscribed or similar services. You can object to these communications at any time.
10. Your Rights (GDPR)
In accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act, you have the following rights:
- Right of access : obtain a copy of your personal data
- Right to rectification : correct inaccurate or incomplete data
- Right to erasure : delete your data (subject to legal obligations)
- Right to restriction of processing : limit the use of your data in certain cases
- Right to data portability : receive your data in a structured format
- Right to object : object to processing based on legitimate interest or for prospecting purposes
- Right to withdraw consent : at any time, without affecting the lawfulness of prior processing
To exercise your rights, contact us by email: hello@oriviaa.com. We will respond within a maximum of 30 days. Proof of identity may be requested to verify your identity.
11. Complaint to the CNIL
If you consider that the processing of your personal data constitutes a violation of the GDPR, you have the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL), the French supervisory authority:
12. Policy Updates
ORIVIAA reserves the right to modify this privacy policy at any time to reflect changes in practices or legal obligations. The update date is indicated at the top of the page. By continuing to use the website after modification, you accept the updated policy.
Legal pages: