Privacy policy
ONY - GROUPE SHF
This e-commerce website is published by SARL GROUPE SHF, registered with the Paris Trade and Companies Register under number 919 285 973, with a share capital of €1,000, whose registered office is located at 16 rue Cuvier 69006 Lyon. Intra-community VAT number: FR 06919285973
Publication directors: Simon Joanin / Samir Rihani
Definition:
Shop: the website https://www.my-ony.com/
Customer: the natural person who, acting in a professional or commercial capacity, enters into an agreement with the company GROUPE SHF.
The purpose of this privacy policy is to inform users of our shop about the personal data we collect, as well as the following information, where applicable:
1. The personal data we collect.
2. The use of the data collected.
3. Who has access to the data collected.
4. The rights of shop users.
5. The cookie policy of the shop.
This privacy policy operates alongside the shop's general terms and conditions of use.
Applicable laws:
In accordance with the General Data Protection Regulation (GDPR), this privacy policy complies with the following regulations.
Personal data must be:
- Processed in a lawful, fair and transparent manner in relation to the data subject (lawfulness, fairness, transparency);
- Collected for specified, explicit and legitimate purposes, and not further processed in a manner incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not, in accordance with Article 89(1), be considered incompatible with the initial purposes (purpose limitation);
- Adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (data minimisation);
- Accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (accuracy);
- Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1), subject to implementation of the appropriate technical and organisational measures required by the regulation in order to safeguard the rights and freedoms of the data subject (storage limitation);
- Processed in a manner that ensures appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (integrity and confidentiality).
Processing is lawful only if, and to the extent that, at least one of the following conditions is met:
- The data subject has given consent to the processing of their personal data for one or more specific purposes;
- Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
- Processing is necessary for compliance with a legal obligation to which the controller is subject;
- Processing is necessary in order to protect the vital interests of the data subject or of another natural person;
- Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
For residents of the State of California, this privacy policy aims to comply with the California Consumer Privacy Act (CCPA). If there are any inconsistencies between this document and the CCPA, the state legislation shall apply. If we identify any inconsistencies, we will amend our policy to comply with the relevant law.
Consent:
Users agree that by using our shop, they consent to:
The terms set out in this privacy policy and the collection, use and retention of the data listed in this policy.
Article 1. What personal data do we collect?
Automatically collected data:
When you visit and use our shop, we may automatically collect and store the following information:
- IP address;
- Location;
- Hardware and software details;
- Links clicked by the user while using the shop;
- Content viewed by the user on the shop.
Data collected non-automatically:
We may also collect the following data when you perform certain functions on our shop:
- First name and surname;
- Age;
- Date of birth;
- Gender;
- Email;
- Phone number;
- Home address;
- Autofill data;
- Choices regarding commercial prospecting;
- Cart/wish list;
- Order total.
This data may be collected when the user creates a customer account or completes the order process on the shop.
Please note that we only collect data that helps us achieve the purpose set out in this privacy policy.
We will not collect any additional data without informing you beforehand.
Article 2. How do we use personal data?
Personal data collected on our shop will be used solely for the purposes specified in this policy or indicated on the relevant pages of our shop. We will not use your data beyond what we disclose.
The data we collect automatically is used for the following purposes:
- Statistics;
- Improving the ease of use of our shop.
The data we collect when the user performs certain functions may be used for the following purposes, depending in particular on your choices regarding commercial prospecting:
- Processing your order;
- Delivery of your order to the chosen delivery address;
- Payment for your order;
- Refund of your order;
- For communication purposes such as e-mailing, SMS marketing or remarketing;
- Improving the ease of use of the shop;
- Statistics;
- After-sales service management;
- Referral campaign.
E-mail prospecting:
GROUPE SHF complies with the rules set out in Directive 2002/58/EC of 12 July 2002, which requires the prior express consent of the user for the sending of commercial prospecting by electronic means (e-mail).
When you create your account on the shop, you are expressly asked for your consent to receive offers from GROUPE SHF by e-mail.
GROUPE SHF will not send you personalised solicitations by e-mail or SMS if you have not consented to this.
There is an exception in the case where the user, without having given prior consent, may nevertheless be contacted provided they are already a customer of a company specialising in e-mail marketing and the purpose of the prospecting is to offer similar products or services.
In all cases, the user has the option of objecting to receiving such solicitations by taking the following steps:
By clicking on the unsubscribe link provided in each e-mail or SMS.
By contacting customer service by email: contact@my-ony.com
Article 3. With whom do we share personal data?
Employees:
We may disclose to any member of our organisation the user data they reasonably need to achieve the objectives set out in this policy.
Subcontractors:
We engage service providers acting on our behalf ("subcontractors" within the meaning of the GDPR). We may share with them certain user data, strictly necessary for the performance of their duties.
In particular, we may engage the following subcontractors:
- Payment providers;
- Marketing agency for e-mailing;
- Order preparation and returns / logistics agency;
- Remarketing agency;
- Delivery providers;
- After-Sales Service provider (ticketing tool, customer request management, telephone or chat support);
- Data analytics providers;
- Sales tracking and advertising performance measurement providers;
- Chartered accountancy firm.
Our subcontractors provide services on our behalf, including:
- Logistical management of shipments and returns;
- Bookkeeping and management of tax obligations;
- Securing online payments and combating fraud;
- Management of telephone calls, sending of postal or digital correspondence;
- Personalisation of website content;
- Carrying out maintenance operations and technical developments;
- Collection of customer reviews;
- Provision of analytical solutions or audience measurement statistics.
Subcontractors will not be able to access user data beyond what is reasonably necessary to achieve the given purpose and act in accordance with our contractual instructions and the GDPR.
Some of these providers (in particular payment providers and the accountancy firm, in the context of their legal obligations) may also act as separate data controllers for their own purposes (fraud prevention, legal obligations, etc.); in such cases, their own privacy policies apply.
Other disclosures:
We undertake not to sell or share your data with other third parties, except in the following cases:
- If required by law;
- If it is required for any legal proceedings;
- To prove or protect our legal rights;
- To buyers or potential buyers of this company in the event that we seek to sell the company.
If you follow hyperlinks from our shop to another site, please note that we are not responsible for and have no control over their privacy policies and practices.
How long do we store personal data?
We do not retain user data beyond what is necessary to achieve the purposes for which it was collected.
- Technical data related to the operation of the shop: 1 year from the date of collection.
- Data relating to an active customer in connection with their customer account: for the duration of the contractual relationship.
- Data relating to an inactive customer in connection with contract performance: 10 years after the end of the contract or the last contact from the inactive customer.
- Data relating to an inactive customer in connection with a newsletter subscription: until unsubscription.
- Data relating to an inactive customer in connection with their customer account: until account closure.
How do we protect your personal data?
In order to ensure the protection of your security, we use the transport layer security protocol to transmit personal information within our system.
All data stored in our system is properly secured and accessible only to our employees. Our employees are bound by strict confidentiality agreements, and a breach of this agreement would result in the dismissal of the employee.
While we take all reasonable precautions to ensure that our user data is secure and that users are protected, there always remains a risk of harm. The internet as a whole can sometimes be insecure, and therefore we are unable to guarantee the security of user data beyond what is reasonably practicable.
International data transfers:
User data may be accessed, processed or collected within the European Union.
Article 4. What are your rights as a user?
Under the GDPR, users have the following rights as data subjects:
- Right of access;
- Right to rectification;
- Right to erasure;
- Right to restrict processing;
- Right to data portability;
- Right to object.
You will find further information on these rights in Chapter 3 (Art 12-23) of the GDPR.
How to modify, delete or contest the data collected?
If you would like your information to be deleted or modified in any way, please contact our privacy agent here:
Samir Rihani
16 rue Cuvier 69006 Lyon
contact@my-ony.com
Article 5. Cookie Policy
What is a cookie?
A cookie is a small file stored by a server on a user's device (computer, phone, tablet, etc.) and associated with a web domain (i.e. in most cases, all the pages of the same website). This file is automatically sent back during subsequent contacts with the same domain.
Its purpose is to facilitate the experience for users of our shop, as well as to offer them personalised advertisements and to compile visit statistics.
What cookies do we use?
- Functionality cookies:
"Functionality cookies" allow users to enhance their experience on our shop. These cookies may be activated by the technical team at GROUPE SHF or by third parties. If you do not accept these cookies, the functionality of the shop may be affected.
- Performance cookies:
"Performance cookies" allow us to compile visit statistics with the aim of improving the performance of our shop.
If you do not accept these cookies, your visit will not be recorded in our database.
- Strictly necessary cookies:
"Strictly necessary cookies" enable our shop to function properly and do not store personally identifiable information. These cookies are essential and cannot be disabled.
- Cookies for targeted advertising:
"Cookies for targeted advertising" allow us to show you targeted advertisements on other sites and do not store personally identifiable information. These cookies may be used by third-party companies.
- Social media cookies:
"Social media cookies" make it easy for users to share our content on your social networks. If you do not accept these cookies, you may be blocked if you wish to share content.
You can block cookies at any time (although your user experience on our shop will be affected) by configuring the settings directly in your browser:
Internet Explorer: https://support.microsoft.com
Firefox: https://support.mozilla.org
Google Chrome: https://support.google.com
Safari: https://help.apple.com
Opera: https://help.opera.com
Amendments:
This privacy policy may be amended at any time in order to maintain compliance with the law and to reflect any changes to our data collection process.
We recommend that all our users check this policy regularly to keep informed of any updates. Where necessary, we may notify users by email of changes made to this policy.
Contact:
If you have any questions for us, please do not hesitate to contact us by email or by post:
Email address: contact@my-ony.com
Postal address: 16 rue Cuvier 69006 Lyon
Effective date: 03 September 2022

