Privacy Policy
Regulation (EU) 2016/679 — GDPR Compliance
Controller:
OrderManagementPoint
OrderManagementPoint, registered at 64 Rue Vieille du Temple, 75003 Paris, France, acts as data controller for personal data submitted through our website, project briefs, and service correspondence. Questions regarding this policy may be directed to [email protected].
1. Categories of Data Processed
We process identification and contact details (name, business email, telephone, organisation), correspondence content (project specifications, commercial interests), and limited technical logs (IP address, browser metadata, consent preferences) required to operate and secure our digital services.
2. Purposes and Legal Bases
Personal data is processed on the following legal bases: (a) performance of a contract or pre-contractual measures requested through project briefs; (b) legitimate interests in responding to business enquiries, securing our systems, and improving service delivery; and (c) consent for optional analytics or marketing communications, which may be withdrawn at any time.
3. Recipients and International Transfers
Data is shared only with processors who support our operations (cloud hosting, email delivery, payment infrastructure) under appropriate contractual safeguards. Delivery infrastructure is maintained within the European Union. Where a transfer outside the EEA is required, we rely on Standard Contractual Clauses or equivalent legal mechanisms.
4. Retention
Enquiry correspondence is retained for up to twenty-four (24) months unless a contractual relationship is established, in which case records are retained for the duration of the engagement and thereafter for statutory commercial and tax retention periods applicable in France.
5. Your Rights
Subject to applicable law, you may request access to, rectification of, erasure of, restriction of, or portability of your personal data, and you may object to processing based on legitimate interests. You also have the right to lodge a complaint with a supervisory authority, including the Commission Nationale de l'Informatique et des Libertés (CNIL). Requests may be addressed to [email protected].
6. Security
We implement technical and organisational measures — including access controls, encryption in transit, and EU-hosted processing — designed to protect personal data against unauthorised access, alteration, or disclosure.