Home › Privacy & GDPR

Privacy Policy & Data Protection

At Les idées de la forêt, we process your personal data in full compliance with the EU General Data Protection Regulation (GDPR) and French data-protection law.

Read this page in English

Dernière mise à jour : 8 septembre 2026

Our commitment

Les idées de la forêt is committed to fully complying with the European and French regulations applicable to the protection of personal data, in particular Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and the French Data Protection Act No. 78-17 of 6 January 1978 ("Informatique et Libertés") as amended. We apply the principles of lawfulness, data minimization, transparency, security, and respect for your rights at every stage of processing.

1. Who is the data controller?

The controller of the data collected on this website is:

For any question relating to the protection of your data, you can write to us at this address with "GDPR" in the subject line. Our full company details are set out in our legal notice (in French).

2. What data do we collect?

We only collect the data strictly necessary for the purposes described below:

3. Why? Purposes and legal bases

Each processing operation is based on a legal basis provided for by Article 6 of the GDPR:

4. Who has access to your data?

Your data is never sold. It is accessible to our team and to carefully selected processors, acting on our instructions and contractually bound to comply with the GDPR:

5. Transfers outside the European Union

Some of our providers may process data outside the European Union. In such cases, these transfers are strictly governed by the safeguards provided for by the GDPR: the European Commission's Standard Contractual Clauses, or adherence to the EU-US Data Privacy Framework. We make sure that a level of protection equivalent to that of the European Union is maintained.

C'est notamment le cas de Microsoft pour l'outil Clarity (Microsoft Ireland Operations Limited pour l'Union européenne, Microsoft Corporation aux États-Unis), qui adhère au Data Privacy Framework UE–États-Unis et applique les clauses contractuelles types. Ce transfert n'a lieu que si vous avez consenti à l'analyse du comportement de navigation ; en cas de refus, aucune donnée ne lui est transmise.

6. How long do we keep your data?

7. Your rights

In accordance with the GDPR and the French Data Protection Act, you have the following rights over your data at any time:

8. How to exercise your rights

Simply write to us at contact@lesideesdelaforet.com. We will reply within a maximum of one month. Proof of identity may be requested if there is reasonable doubt about your identity.

If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the French data-protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL) — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.

9. Cookies and trackers

Notre site utilise uniquement les cookies nécessaires à son bon fonctionnement (session, panier, authentification) ainsi que des cookies de mesure d'audience. Les cookies non essentiels ne sont déposés qu'avec votre consentement, que vous pouvez retirer à tout moment via les réglages de votre navigateur. Aucun cookie publicitaire tiers n'est utilisé à des fins de revente de données. Notre mesure d'audience est réalisée avec notre propre outil, pour nos seuls besoins et sans recoupement : elle relève de l'exemption de consentement prévue par la CNIL, et vous pouvez malgré tout vous y opposer d'un clic depuis notre politique de cookies, où figure également la liste complète des traceurs avec leur finalité et leur durée de vie.

Un seul traceur est soumis à consentement : Microsoft Clarity, qui analyse le comportement de navigation. Un bandeau vous demande votre accord avant tout dépôt ; refuser y est aussi simple qu'accepter et n'a aucune conséquence sur l'accès au site. Vous pouvez revenir sur votre choix à tout moment via le lien « Gérer mes cookies » en bas de chaque page.

10. Security of your data

We implement appropriate technical and organizational measures to protect your data: encryption of exchanges (HTTPS), password encryption, strict access control, hosting on secure infrastructure, and outsourcing of payment to a PCI-DSS certified provider. In the event of a data breach likely to create a risk to your rights, we would notify the CNIL and, where applicable, the individuals concerned, within the time limits set by the GDPR.

11. Protection of minors

Our website is intended for an adult audience. We do not knowingly collect data concerning minors under the age of 15 without the consent of the holders of parental authority.

12. Changes to this policy

This privacy policy may change to reflect changes in our practices or in regulations. Any substantial modification will be indicated on this page, whose last-updated date appears at the top of the document.

A question about your data?

We are here to help and will reply within one month.

Contact us