Legal Information
Privacy Policy
Official versionThe Catalan version of this document shall prevail. View the Catalan version
1. DATA CONTROLLER
The personal data controller is:
BENOIST ROUSSEAU SLU
20 carrer Josep Viladomat, Parc de la Mola 3
AD700 Escaldes-Engordany
Andorra
Email: benoist@benoistrousseau.com
2. COLLECTED DATA
The data that may be collected are:
- First and last name
- Email address
- IP address
- Connection data
- Browsing data
- Messages sent via form or comments
No automated decision having a legal effect is made based on your data. No profiling is carried out.
3. PURPOSES OF PROCESSING
The data are collected for:
- management of user accounts
- sending of newsletters
- improvement of the user experience
- prevention of fraud and spam
- legal and administrative obligations
4. LEGAL BASIS
The processing of data is based on:
- for the newsletter, the user's consent
- for security, the legitimate interest of the data controller
- for requests via the contact form, the user's consent
5. NEWSLETTER
Subscription to the newsletter is voluntary.
It relies on a double opt-in system:
- initial registration
- confirmation via email
Without confirmation, the data are deleted within a period of 7 days.
Each email contains an unsubscribe link allowing:
- the immediate cessation of mailings
- the deletion of data within 7 days
6. COMMENTS AND FORMS
When publishing a comment or a message:
- the entered data
- the IP address
- the date and time
may be recorded in order to:
- fight against spam
- ensure the security of the site
7. COOKIES
The site uses strictly necessary cookies:
- technical operation
- session management
- user preferences
No advertising cookie is used.
Duration:
- session cookies: temporary
- preference cookies: up to 1 year
The user may delete cookies via their browser.
8. THIRD-PARTY CONTENT
The site may integrate external content.
These services may:
- collect data
- place cookies
- track user activity
The publisher is not responsible for the policies of these services.
9. DATA RECIPIENTS AND TRANSFERS
Personal data may be transmitted only to the providers strictly necessary for the provision of the service, in accordance with the Llei 29/2021, del 28 d'octubre, qualificada de protecció de dades personals (Andorran qualified law on personal data protection, LQPD). No data is sold, rented, or transferred for commercial purposes.
Providers and data processors:
| Provider | Publisher | Country of processing | Purpose | Transfer safeguard | Privacy Policy |
|---|---|---|---|---|---|
| o2switch | o2switch SAS | France (EU) | Hosting of the site and data | Adequate level of protection | https://www.o2switch.fr/mentions-legales |
| GetResponse | GetResponse SA (Poland) | Poland (EU) | Management and sending of the newsletter | Data Processing Agreement (DPA) compliant with Article 28 of the GDPR; standard contractual clauses (Art. 39 LQPD) for any data processors outside the EU | https://www.getresponse.com/legal/privacy |
Details on transfers outside Andorra and outside the EU
Certain providers may process personal data outside Andorra and the European Union, notably in the United States. In accordance with Article 39 of the Llei 29/2021, these transfers are governed by the following mechanisms:
- Standard Contractual Clauses (SCC): contracts compliant with the models approved by the competent authorities, guaranteeing a level of data protection equivalent to that provided by the LQPD and the GDPR;
- Data Processing Agreements (DPA): data processing agreements concluded with each data processor, defining the respective obligations regarding security, purpose, and duration of the processing;
- Adequate level of protection: for providers located in the EU or in countries recognized as offering an adequate level of protection.
Special case: GetResponse
The newsletter service is provided by GetResponse SA, a company incorporated under Polish law, whose processing infrastructures are located in the European Union (Poland). The data of newsletter subscribers (email address, connection data, interactions with emails) are processed in the EU. The processing is governed by a Data Processing Agreement compliant with Article 28 of the GDPR; any potential recourse by GetResponse to data processors located outside the European Union is governed by standard contractual clauses ensuring an equivalent level of protection.
The user may consult the GetResponse DPA at the following address: https://www.getresponse.com/legal/data-processing-agreement
Commitments of BENOIST ROUSSEAU SLU
BENOIST ROUSSEAU SLU commits to:
- only use data processors providing sufficient guarantees regarding data protection;
- conclude a processing agreement compliant with the LQPD with each data processor;
- inform users of any change of data processor involving a transfer to a third country;
- update this list in the event of the addition or removal of a provider.
This list is updated in the event of the addition or removal of a provider. The date of the last update appears at the bottom of this document.
10. RETENTION PERIOD
Personal data are retained according to the following periods:
- Newsletter: 7 days after unsubscription
- Comments: 5 years from the last activity of the account, or the lifespan of the commented content
- Messages sent via the contact form: retained for the time of processing the request, then deleted no later than 12 months after the last exchange
11. USER RIGHTS
In accordance with the Llei 29/2021, the user has the following rights over their personal data:
| Right | Description |
|---|---|
| Access | Obtain confirmation that data concerning you are being processed and receive a copy thereof |
| Rectification | Have inaccurate data corrected or incomplete data completed |
| Deletion | Request the erasure of your data when they are no longer necessary for the purpose for which they were collected |
| Objection | Object, on legitimate grounds, to the processing of your data |
| Restriction | Request the restriction of processing in certain circumstances |
| Portability | Receive your data in a structured, commonly used, and machine-readable format |
How to exercise your rights
Any request may be sent by email to:
To facilitate the processing of your request, please specify:
- the right you wish to exercise;
- your contact details (first name, last name, email address associated with your account);
- any element allowing you to be identified as a user of the site.
The exercise of these rights is free of charge. However, in the event of manifestly unfounded or excessive requests, in particular because of their repetitive character, BENOIST ROUSSEAU SLU may demand the payment of reasonable fees or refuse to act on the request, by providing reasons for its decision.
Response times
BENOIST ROUSSEAU SLU commits to acknowledging receipt of your request within 72 hours.
A reasoned response will be communicated to you within a maximum period of one (1) month from the receipt of the request, in accordance with the LQPD.
This period may be extended by two (2) additional months if the complexity or the number of requests justifies it. In this case, BENOIST ROUSSEAU SLU will inform you of the extension and its reasons within the initial period of one month.
In the event of a refusal, the response will specify the reasons for the refusal as well as the possibility of lodging a complaint with the supervisory authority.
Identity verification
BENOIST ROUSSEAU SLU may ask you to provide proof of identity in order to ensure that the request indeed originates from the data subject concerned. This verification aims to protect your data against any unauthorized access.
Complaint to the supervisory authority
If you consider that your rights regarding data protection are not respected, you may lodge a complaint with the Andorran Data Protection Agency (APDA):
12. SECURITY
BENOIST ROUSSEAU SLU implements:
- technical measures
- organizational measures
in order to protect personal data.
13. MODIFICATION OF THIS POLICY
Right of modification
BENOIST ROUSSEAU SLU reserves the right to modify this Privacy Policy at any time, notably to adapt it to legal, regulatory, or technical developments, or to changes affecting the data processing implemented.
Minor modifications
Minor modifications (typographical corrections, reformulations without impact on user rights, link updates) enter into force upon their publication on the site. The date of the last update appearing at the bottom of the document is authoritative.
Substantial modifications
Any substantial modification of this policy will be subject to a notification to users with an account, by email, at least 30 days before its entry into force.
Modifications relating notably to the following are considered substantial:
- the purposes of the processing of personal data;
- the categories of collected data;
- the recipients or data processors having access to the data;
- data transfers to a new third country;
- retention periods;
- the modalities for exercising user rights;
- the addition of tracking technologies or cookies that are not strictly necessary.
The notification will specify the nature of the modifications made, the date of entry into force, and the link to the full version of the updated policy.
Consultation and objection
The user is invited to regularly consult this policy.
If the user objects to a substantial modification, they may:
- exercise their rights of deletion and objection in accordance with Article 11 of this policy, by sending a request to benoist@benoistrousseau.com;
- unsubscribe from the newsletter via the link provided for this purpose;
- request the deletion of their account in accordance with the conditions provided in the Terms of Use.
Version history
The applicable version is the one in force on the site at the time of browsing or using the service.
14. APPLICABLE LEGISLATION
This policy is governed by Andorran law.
In the event of a dispute, the Andorran courts have jurisdiction, subject to the mandatory provisions applicable in the user's country of residence.
15. PERSONAL DATA BREACH MANAGEMENT
Definition
A personal data breach means any security incident leading, accidentally or unlawfully, to the destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data processed by BENOIST ROUSSEAU SLU.
This includes notably:
- an intrusion or unauthorized access to IT systems;
- the loss or theft of equipment containing personal data;
- the accidental sending of personal data to an incorrect recipient;
- the accidental deletion of data without the possibility of restoration;
- any incident affecting the confidentiality, integrity, or availability of the data.
Internal detection and evaluation procedure
Upon becoming aware of an incident likely to constitute a data breach, BENOIST ROUSSEAU SLU commits to:
- Contain the incident: immediately take the necessary technical measures to limit the extent of the breach (suspension of access, change of passwords, isolation of the affected systems).
- Evaluate the breach: determine as soon as possible the nature of the incident, the categories and volume of data concerned, the categories and approximate number of affected persons, and the likely consequences of the breach.
- Document the incident: record all facts relating to the breach, its effects, and the corrective measures taken. This register is retained and kept at the disposal of the APDA.
Notification to the Andorran Data Protection Agency (APDA)
In accordance with the Llei 29/2021, when the breach is likely to result in a risk to the rights and freedoms of the data subjects, BENOIST ROUSSEAU SLU will notify the APDA as soon as possible and no later than 72 hours after having become aware of it.
The notification will contain:
- the description of the nature of the breach;
- the categories and approximate number of data subjects concerned;
- the categories and approximate volume of data concerned;
- the likely consequences of the breach;
- the measures taken or proposed to address the breach and mitigate its effects.
If all of this information cannot be provided within the 72-hour period, the notification will be made in phases, with additional information being transmitted as soon as it is available. Any exceeding of the 72-hour period will be accompanied by a justification.
Information of the data subjects
When the breach is likely to result in a high risk to the rights and freedoms of the data subjects, BENOIST ROUSSEAU SLU will inform them without undue delay, in clear and plain language.
This communication will specify:
- the nature of the breach;
- the likely consequences;
- the measures taken to address it;
- the recommendations to follow to protect oneself (change of password, increased vigilance, etc.);
- the contact details of the point of contact for any questions.
Exceptions to the information of persons
The individual information of the data subjects is not required when:
- appropriate protective measures were implemented beforehand, rendering the data unintelligible to any unauthorized person (encryption notably);
- subsequent measures have been taken ensuring that the high risk will no longer materialize;
- individual information would require disproportionate efforts, in which case a public communication will be made.
Contact
In the event of a question relating to the security of your data, you may contact BENOIST ROUSSEAU SLU at the following address:
If you consider that your rights have not been respected following an incident, you may lodge a complaint with the APDA: www.apda.ad
Language of the document. This Privacy Policy is drawn up in Catalan, the official language of the Principality of Andorra, and the Catalan version is authentic. The French version and other translations are made available for the convenience of the user. In the event of a discrepancy between the Catalan version and any of its translations, the Catalan version shall prevail.