1. Data controller
The data controller is BURJ SPRL, 112 avenue Stalingrad, 1000 Bruxelles, Belgique.
Privacy contact: support@atelier-kelvin.com
2. Processed data (strict necessity)
We only collect data required to deliver the e-commerce service:
- Identity/account: first name, last name, email, hashed password, sign-in history.
- Order/shipping: addresses, cart contents, orders, logistics statuses.
- Payment: transaction status, payment provider reference, amount and currency (no full card number stored).
- Customer support: contact form messages and anti-abuse metadata.
- Security: technical logs, IP metadata and authentication/audit traces.
3. Purposes and legal bases
Processing relies on the following legal grounds:
- Contract performance: account, order, payment, shipping, after-sales.
- Legal obligations: invoicing, accounting, tax and consumer law compliance.
- Legitimate interest: fraud prevention, security and service quality.
- Consent: only for optional processing (e.g. newsletter).
4. Recipients and processors
Data may be shared strictly with:
- Payment providers for transaction execution and fraud prevention.
- Carriers (DHL / DPD) for order delivery.
- Technical providers for hosting, monitoring and security.
- Public authorities when legally required.
5. Retention periods
Retention is limited and proportionate:
- Customer account: while active, then deletion/anonymization after prolonged inactivity.
- Order/invoicing data: statutory accounting and tax periods.
- Security logs: limited period aligned with abuse prevention.
- Support tickets: processing period plus limited archive.
6. Your rights
Under GDPR, you may request:
- Access, rectification, erasure and restriction.
- Objection to processing based on legitimate interest.
- Data portability where applicable.
- Withdrawal of consent at any time for relevant processing.
You may also lodge a complaint with the Belgian Data Protection Authority if you believe your rights are not respected.
7. Cookies and trackers
We use strictly necessary cookies for secure site operation (session, cart, CSRF, technical preferences). Non-essential cookies, if enabled later, remain consent-based.
8. Data security
We apply strong technical and organizational safeguards: encryption in transit, access control, logging, infrastructure hardening, least-privilege and continuous security review.
Last update: 2026-04-01