Privacy policy
Version 1.0. Effective 3 October 2026. This is a translation of the French version, which is the reference version.
This page explains what data we collect on notmydpt.com, why, for how long, and what your rights are.
1. Who is responsible for your data
The data controller is EVENT & SAFETY ENGINEERING (ESE), operating the NOT MY DPT brand, a French SAS with a sole shareholder, 15 rue des Halles, 75001 Paris, France, Paris RCS no. 951 249 937.
Contact for any question about your data: support@notmydpt.com, or by post to the address above, marked "Personal data".
We have not appointed a data protection officer, as our activity does not require one.
2. What we process, why, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Process your order, have it made and delivered, keep you informed | Name, email, delivery and billing address, phone number (if required by the carrier), order contents and amount | Performance of the contract |
| Take payment and prevent fraud | Payment status and identifier, last four digits and type of card, anti-fraud signals collected by Stripe. We never have access to your full card number | Performance of the contract; legitimate interest (payment security) |
| Answer your requests (ASK PROD.), handle withdrawals, returns, guarantees and complaints | Identity, contact details, order number, content of exchanges, photos you send | Performance of the contract; legal obligation |
| Keep our accounts and meet our tax and legal obligations (invoicing, contract archiving, product safety) | Order and billing data, product safety complaints | Legal obligation |
| Send you the RADIO CHECK newsletter | Email address, date and proof of sign-up, language | Consent, which you may withdraw at any time |
| Measure website audience in order to improve it | Pages viewed, visit source, device and browser type, country or region. Aggregated traffic statistics, no cross-site tracking | Legitimate interest (strictly necessary audience measurement, exempt from consent) |
| Keep the website secure and running | IP address, technical logs, browser | Legitimate interest (security) |
| Answer requests to exercise your rights | Identity, contact details, content of the request | Legal obligation |
Information marked as mandatory in forms is required to process your order. Without it we cannot fulfil it.
We do not create customer accounts, we do no advertising profiling, and we neither sell nor rent your data.
Automated anti-fraud checks are run by our payment provider. A payment may be declined on that basis. You can contact us to have the situation reviewed.
3. Who receives your data
Your data is accessible only to those who need it at ESE, and to our service providers within the limits of their task:
| Recipient | Role | Country |
|---|---|---|
| Stripe Payments Europe, Limited | Online payment and fraud prevention. Stripe acts as a processor for taking payment, and as a controller for its own obligations (fraud, compliance) | Ireland, with possible transfers to the United States |
| Prodigi Group Ltd (United Kingdom) and its group companies, including Prodigi B.V. (Netherlands), and its partner workshops | On-demand production and shipping: receives your name, delivery address, contact details for the carrier and order contents | United Kingdom and European Union; other countries may be involved depending on the workshop and carrier (see section 4) |
| Carriers (postal services and couriers) | Delivery | Countries of production and delivery |
| Vercel Inc. | Website hosting, technical logs | United States and European Union |
| Brevo (Sendinblue SAS) | Sending order emails and the newsletter | European Union |
| Plausible Insights OÜ | Traffic statistics, without cookies or personal data | European Union |
| Accountant, advisers, consumer mediator, authorities | Accounting obligations, dispute handling, legal requests | France |
The detailed list of our processors is available on request.
4. Transfers outside the European Union
Some providers are established outside the European Union or have data processed there:
- United Kingdom (Prodigi): the United Kingdom benefits from an adequacy decision of the European Commission, which recognises a level of protection equivalent to that of the Union.
- Other countries (Prodigi): Prodigi's contract provides that order data may also be processed in the United States, Australia or transit countries, depending on the workshop and carrier. These transfers are covered by the European Commission's standard contractual clauses.
- United States (Stripe, Vercel): these providers are certified under the EU-US Data Privacy Framework, and our contracts with them include the European Commission's standard contractual clauses.
You can obtain a copy of the applicable safeguards by writing to us.
5. How long we keep your data
| Data | Retention |
|---|---|
| Orders, invoices and accounting records | 10 years from the end of the financial year |
| Contracts concluded online for €120 or more | 10 years from delivery |
| Customer data used for the business relationship | During the business relationship, then 3 years from your last order or last contact |
| Exchanges with customer service, return and guarantee files | 5 years from closure of the file (limitation period) |
| Newsletter | Until you unsubscribe, and no later than 3 years after your last contact (for example a click in an email). Your address is then kept on a suppression list so that we stop writing to you |
| Proof of your consent | For the duration of the subscription, then 5 years |
| Payment data | Not kept by ESE. Stripe keeps it under its own policy |
| Audience statistics | 25 months at most |
| Website technical logs | 30 days at most |
| Product safety complaints | 5 years at most for the personal data in the register |
| Requests to exercise rights | For the time needed to handle them, then archived for the applicable limitation period |
At the end of these periods, data is deleted or anonymised.
6. Your rights
You have the following rights over your data:
- access, rectification, erasure;
- restriction of processing;
- objection to processing based on our legitimate interest, including audience measurement (see the cookie policy);
- portability of the data you provided;
- withdrawal of your consent at any time, for example using the unsubscribe link in every newsletter;
- under French law, the right to set instructions for what happens to your data after your death.
To exercise your rights, write to support@notmydpt.com. We reply within one month. Proof of identity is requested only where there is reasonable doubt about your identity.
You may also lodge a complaint with the French data protection authority, the CNIL: 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr. If you live in another European Union country, you may contact the data protection authority of your country.
7. Minors
The website is not aimed at minors under 15 and we do not knowingly collect their data.
8. Security
Exchanges with the website are encrypted (HTTPS). Payments are processed by Stripe, a PCI-DSS certified provider. Access to order data is limited to authorised persons. In the event of a data breach creating a risk for you, we inform the CNIL and, where necessary, you, as required by law.
9. Changes
We may update this policy. The version date is shown at the top of the page. In the event of a significant change, we will inform you by a notice on the website or by email.