Trust Center

Group-wide privacy notice

Privacy Notice

This notice explains how Lornez Group handles personal data through its corporate and business websites, commercial communications, and the Business Management application used with authorized Facebook, Instagram, and Threads integrations.

Effective and last updated: 18 August 2026
01

Scope and controller

The controller for the processing described in this notice is LORNEZ GROUP, Société par actions simplifiée (SAS), registered at 36 rue Scheffer, 75016 Paris, France, SIREN 102 360 724.

This notice applies to the Lornez Group corporate website, the group business websites listed below, group-level business communications, and authorized platform integrations operated by Lornez Group:

A specific service, campaign, form, contract, or business website may provide additional information. Where that information is more specific, it supplements this notice for the relevant processing.

Data protection contact

Contact the Lornez Group privacy team at lornez@lornez.com. Lornez Group does not publicly claim that a statutory Data Protection Officer has been appointed. If that position changes, the verified contact will be published here.

02

Data we process

The categories processed depend on how you interact with us. We seek to collect only what is relevant to the stated purpose.

Website and business communications

  • Identity and professional details, such as name, company, organization, role, country, and market.
  • Contact details, including business email address and any contact details you voluntarily include in a message.
  • Inquiry content, product specifications, project requirements, quantities, delivery market, budget information, and attachments you choose to provide.
  • Contract, order, invoicing, payment-status, delivery, and after-sales records when a commercial relationship is established.
  • Technical and security information, such as IP address, submission time, source page, browser request information, and security logs.

Information from other sources

We may receive business contact information from a colleague, an authorized representative, a business partner, a public professional source, or a platform integration. Where required, we provide the relevant information about that processing at or before our first substantive communication.

Please do not send passwords, access tokens, full payment-card details, government identity documents, health information, or other sensitive personal data unless we have specifically requested it through an appropriate secure channel.

Tableware measurement data

When the corresponding production tag has been enabled and the visitor has granted the relevant cookie choice, tableware.lornez.com may process limited analytics or advertising-measurement data. This may include a pseudonymous browser identifier, IP-derived and device or browser information, pages and interactions, consent status, campaign parameters, advertising click identifiers, and a technical event showing that an RFQ was successfully submitted.

Tableware Meta Pixel and Conversions API

If the Tableware Meta integration is enabled in production, it runs only after the visitor has expressly selected the Advertisingcategory. It uses Meta Pixel in the browser and Meta's Website Conversions API (CAPI) from the server to measure PageView, ViewContent for an RFQ page, and a successful Lead submission. The purposes are advertising attribution, measurement, and delivery optimization.

The data sent to Meta may include the event name and time, a server-generated event ID, IP address, browser user-agent, current _fbp or _fbc values where present, and the fbclid advertising-click value where available. For a successful Lead, the email address is transformed into a one-way hash before CAPI transmission; the plain-text email is not sent to Meta through this integration. Necessary page and source information is minimized to an approved Tableware path and permitted campaign parameters.

RFQ form details are kept separate

The Google measurement setup and the Meta integration do not receive the RFQ message or product requirements, quantities, attachments, telephone number, company details, or plain-text email through the Meta event. Browser and CAPI copies of the same event use the same server-generated event ID so Meta can deduplicate them; this is not two separate Leads.

03

Purposes and legal bases

PurposeTypical dataLegal basis
Respond to inquiries and prepare proposalsIdentity, company, contact details, request contentSteps requested before a contract; legitimate interests in business communications
Perform orders, contracts, and after-sales supportContact, contract, order, delivery, and payment recordsPerformance of a contract; legal obligations
Operate authorized platform integrationsPlatform identifiers, permissions, content and insight dataPerformance of the requested service; consent where required; legitimate interests in managing authorized business channels
Protect websites, systems, and usersIP address, logs, request metadata, security reportsLegitimate interests in security, fraud prevention, and service integrity; legal obligations where applicable
Meet accounting, tax, sanctions, and legal requirementsCompany, transaction, invoice, and due-diligence recordsLegal obligations; establishment or defense of legal claims
Optional analytics or campaign measurementConsent choices, device or campaign data where enabledConsent where required by applicable law
Measure Tableware RFQ and campaign performance with MetaAdvertising consent, event and page data, technical identifiers, IP address, user-agent, Meta click/browser identifiers, and a hashed email for a successful Lead where availableConsent

When processing relies on legitimate interests, we consider the necessity of the activity, the impact on the individual, and reasonable expectations. You may object as described under Your rights.

We do not use the information covered by this notice to make a decision based solely on automated processing that produces legal or similarly significant effects.

04

Meta platform data

This section applies when an individual or authorized business administrator connects, authorizes, or interacts with the Lornez Group Business Management application through Facebook, Instagram, or Threads.

Data that may be received

Depending on the feature used, the permissions approved, and the Meta product involved, we may receive:

  • An app-scoped user identifier and basic account information made available by the approved permission.
  • Facebook Page, Instagram professional account, or Threads account identifiers and account metadata.
  • Content, post, media, comment, message, mention, or publishing metadata only where the relevant feature and permission are used.
  • Engagement, reach, insight, or performance information made available to an authorized business account.
  • Permission status, authorization time, token status, and technical logs needed to maintain and secure the connection.
What we do not receive

Lornez Group does not ask for or receive your Facebook, Instagram, or Threads password. Do not send passwords or access tokens by email.

How platform data is used

  • To provide the integration or management feature you authorize.
  • To publish, retrieve, organize, moderate, respond to, or measure content where the approved feature requires it.
  • To maintain permissions, troubleshoot failures, prevent misuse, and keep an audit trail of administrative actions.
  • To comply with Meta Platform Terms, applicable law, and valid deletion or rights requests.

Platform data is not sold. It is not used to build unrelated advertising profiles. We do not request permissions that are not needed for an implemented feature.

Meta independently processes information under its own terms and privacy policy. Your Meta account settings and permissions remain available through the relevant Meta product.

Tableware Meta Business Tools

The Tableware Pixel/CAPI measurement described above is separate from a person authorizing the Business Management application. Meta processes information it receives through its Business Tools under its own terms and privacy policy. A Tableware cookie choice controls whether Lornez sends new Pixel or CAPI events from this integration; it does not control or limit all of Meta's independent processing, including processing under the visitor's Meta account settings or Meta's own policies.

05

Recipients and transfers

Access is limited to people and service providers who need the information for an authorized purpose. Recipients may include:

  • Authorized Lornez Group personnel and relevant group operating teams.
  • Hosting, database, email, cybersecurity, professional-adviser, logistics, accounting, and business-system providers acting under appropriate terms.
  • Meta, where the Tableware Meta integration is enabled and the visitor has selected Advertising, for Pixel/CAPI event data described above, and where necessary to use, administer, secure, or comply with an applicable platform integration.
  • Google, when the relevant Tableware production tag has been enabled and only for the analytics or advertising-measurement categories selected by the visitor. Google Tag Manager is used to manage the permitted tags, Google Analytics 4 to measure website use, and Google Ads to measure conversions and advertising-click attribution. This Tableware setup does not use enhanced conversions, advertising personalization, remarketing audiences, or cross-site profiling.
  • Public authorities, courts, regulators, or professional advisers where disclosure is required or legally justified.
  • A successor organization in a genuine corporate transaction, subject to appropriate confidentiality and legal safeguards.

Some providers or platform operations may involve countries outside the European Economic Area. Where European data-protection law requires a transfer mechanism, we rely on an adequacy decision, approved contractual safeguards such as Standard Contractual Clauses, or another lawful basis, together with supplementary measures where appropriate.

You may contact us for more information about safeguards relevant to your data.

06

Retention

We keep personal data only for as long as necessary for the purpose, required by law, or needed to establish, exercise, or defend legal claims. The following periods are our ordinary working limits:

RecordOrdinary retention
Business inquiry with no resulting contractUp to 3 years after the last substantive interaction, unless an earlier deletion or objection applies
Contract, order, invoice, and accounting recordsThe contract lifecycle and applicable statutory period, commonly up to 10 years for accounting evidence
Website and security logsNormally up to 12 months, with shorter operational logs where practical and longer retention only for an incident or claim
Tableware cookie consent choiceUp to 180 days (approximately 6 months), after which a renewed choice may be requested; the visitor may change the choice earlier through Cookie settings
Tableware first-touch attribution storageA first-party browser localStorage record is treated as expired 90 days after it is recorded and is automatically deleted when the site next runs and checks it. Browser localStorage does not expire independently while the site is not running. UTM parameters, landing page, and referrer are stored only after analytics consent; gclid, gbraid, and wbraid are stored only after advertising consent. Withdrawing a category removes its data, refusing both optional categories removes the entire record, and clearing browser data may remove it earlier
Tableware analytics identifiersTypical Google Analytics cookies such as _ga and _ga_* may last up to approximately 2 years, depending on configuration, browser controls, consent withdrawal, and Google's service operation
Tableware advertising-attribution identifiersTypical _gcl_* storage, including _gcl_au where applicable, is commonly retained for around 90 days, but the actual period may vary with configuration and Google's service operation
Tableware Meta Pixel/CAPI event informationLornez does not use this disclosure to state a separate Meta retention period. Meta retains information it receives under its own policies and controls. Our related RFQ and security records follow the applicable inquiry and log periods above.
Meta authorization tokensUntil expiry, revocation, disconnection, or loss of the operational need
Meta app-scoped dataWhile the authorized integration is active; deletion is initiated after disconnection or a valid request and normally completed within 30 days, subject to lawful exceptions
Privacy and deletion request recordsAs needed to complete the request and demonstrate compliance, normally up to 3 years after closure

Backups may retain residual copies for a limited rotation period. Such copies remain protected, are not restored for ordinary use, and are overwritten under the applicable backup schedule.

The browser-cookie and localStorage periods above do not state how long data is retained inside Google Analytics. In the current Tableware Google Analytics property, event data retention is set to 2 months and user data retention is set to 14 months. Resetting the user-data retention period on new activity is enabled, so the applicable user-data period starts again when that user identifier records new activity. These property settings do not extend or replace the browser-cookie or localStorage periods described above and do not determine the availability of standard aggregated Analytics reports.

Tableware visitors can revisit or withdraw optional consent through Cookie settings. Withdrawal affects future optional tag activity and does not affect processing that occurred before the choice was changed. It also removes first-touch attribution data for the withdrawn category, or the entire first-touch record when both optional categories are refused. Refusal or withdrawal also stops Lornez from sending new Meta Pixel/CAPI events through the Tableware integration; it cannot withdraw information already received by Meta. Browser controls may also be used to remove cookies or other site data already stored.

07

Your rights

Depending on the processing and applicable law, you may have the right to:

  • Obtain information and access a copy of your personal data.
  • Correct inaccurate or incomplete data.
  • Request deletion where the legal conditions are met.
  • Restrict processing in specified circumstances.
  • Object to processing based on legitimate interests.
  • Object at any time to direct marketing based on your personal data.
  • Receive certain data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Withdraw consent at any time where processing relies on consent, without affecting prior lawful processing.

Send a request to lornez@lornez.com with the subject Privacy Request. Describe the service, website, account, or communication involved. We may request proportionate information to verify identity and protect data from unauthorized disclosure.

For Meta-connected data, use the dedicated Data Deletion Instructions.

You may lodge a complaint with the French data-protection authority, the CNIL, or another competent supervisory authority. We encourage you to contact us first so we can review the issue promptly.

08

Security

We use organizational and technical measures selected for the nature of the data and the relevant risk. These include, as appropriate:

  • Encrypted transport for public websites and database traffic.
  • Role-based access, dedicated service boundaries, restricted administrative access, and least-privilege database permissions.
  • Separation of public website files, runtime configuration, and protected inquiry records.
  • Logging, security review, backup controls, vulnerability response, and credential rotation procedures.
  • Service-provider review and confidentiality or processing terms where appropriate.

No system can be guaranteed absolutely secure. If you believe you have found a vulnerability, use our responsible disclosure channel.

09

Contact and changes

Privacy questions and rights requests may be sent to:

LORNEZ GROUP
36 rue Scheffer, 75016 Paris, France
Email: lornez@lornez.com

This notice may be updated when services, platform permissions, legal requirements, providers, or processing practices change. The effective date appears at the top of the page. Material changes will be communicated through an appropriate channel where required.