1. Data Controller Identification
This Privacy Policy outlines how LA THIERRY (“we,” “our,” or “us”), operating the educational publication Vintoro Health Journal, collects, processes, and safeguards personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the French Data Protection Act (Loi Informatique et Libertés), and applicable global privacy statutes including CCPA.
Data Controller: LA THIERRY
Director / Privacy Officer: Jennifer Johnson
Registration / Tax ID: 1791-9375-9071
Address: 13 All. des Vignes, 94450 Limeil-Brévannes, France
Contact Email: [email protected]
Phone: +33 1 45 10 28 40
2. Categories of Information We Collect
We only collect data strictly necessary to fulfill our educational and communicative mission:
- Voluntary Contact Information: Name, email address, phone number, and inquiry message when you submit our contact or guide request forms.
- Interactive Assessment Inputs: Self-assessment selections are calculated client-side in your browser and are not permanently recorded or tied to your personal identity.
- Technical & Telemetric Data: IP address (anonymized), browser type, operating system, referring URL, and timestamp logs collected for server security and fault troubleshooting.
3. Legal Bases and Purposes of Processing
We process your data under the following legal bases pursuant to Article 6 of the GDPR:
- Legitimate Interests (Art. 6(1)(f) GDPR): Ensuring web infrastructure security, preventing fraud, and maintaining open-access educational journalism.
- Consent (Art. 6(1)(a) GDPR): Direct communication responses when you request educational monographs or reach out via our contact form.
- Legal Obligation (Art. 6(1)(c) GDPR): Compliance with statutory tax, accounting, and regulatory record-keeping rules in France.
4. Data Retention Periods
Inquiry records and email communications are retained for no longer than 24 months after the resolution of the inquiry, after which they are securely expunged, unless longer retention is mandated by French law.
5. Your Statutory Rights Under the GDPR
As a data subject within the European Economic Area or globally, you hold the following non-derogable rights:
- Right to Access (Art. 15 GDPR): Obtain confirmation and copies of your personal data held by us.
- Right to Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete data.
- Right to Erasure / “Right to be Forgotten” (Art. 17 GDPR): Request deletion of your personal data.
- Right to Restriction of Processing (Art. 18 GDPR): Limit how your data is processed.
- Right to Data Portability (Art. 20 GDPR): Receive your data in a structured, machine-readable format.
- Right to Object (Art. 21 GDPR): Object at any time to data processing based on legitimate interests.
To exercise any of these rights, email our Data Protection Officer at: [email protected]. You also have the right to lodge a complaint with the French supervisory authority, CNIL (Commission Nationale de l’Informatique et des Libertés - cnil.fr).
6. Security Measures
We employ end-to-end TLS 1.3 / SSL encryption for all web communications, strict access controls, and server-level hardening to prevent unauthorized access, loss, or disclosure of information.