Scope and controller
The controller for the processing described in this notice is LORNEZ GROUP, Société par actions simplifiée (SAS), registered at 36 rue Scheffer, 75016 Paris, France, SIREN 102 360 724.
This notice applies to the Lornez Group corporate website, the group business websites listed below, group-level business communications, and authorized platform integrations operated by Lornez Group:
- Lornez Group
- R.Lornez Diamond
- Tableware
- Outdoor Living
- The Lornez Group Business Management application and related Facebook, Instagram, and Threads integrations.
A specific service, campaign, form, contract, or business website may provide additional information. Where that information is more specific, it supplements this notice for the relevant processing.
Contact the Lornez Group privacy team at lornez@lornez.com. Lornez Group does not publicly claim that a statutory Data Protection Officer has been appointed. If that position changes, the verified contact will be published here.
Data we process
The categories processed depend on how you interact with us. We seek to collect only what is relevant to the stated purpose.
Website and business communications
- Identity and professional details, such as name, company, organization, role, country, and market.
- Contact details, including business email address and any contact details you voluntarily include in a message.
- Inquiry content, product specifications, project requirements, quantities, delivery market, budget information, and attachments you choose to provide.
- Contract, order, invoicing, payment-status, delivery, and after-sales records when a commercial relationship is established.
- Technical and security information, such as IP address, submission time, source page, browser request information, and security logs.
Information from other sources
We may receive business contact information from a colleague, an authorized representative, a business partner, a public professional source, or a platform integration. Where required, we provide the relevant information about that processing at or before our first substantive communication.
Please do not send passwords, access tokens, full payment-card details, government identity documents, health information, or other sensitive personal data unless we have specifically requested it through an appropriate secure channel.
Purposes and legal bases
| Purpose | Typical data | Legal basis |
|---|---|---|
| Respond to inquiries and prepare proposals | Identity, company, contact details, request content | Steps requested before a contract; legitimate interests in business communications |
| Perform orders, contracts, and after-sales support | Contact, contract, order, delivery, and payment records | Performance of a contract; legal obligations |
| Operate authorized platform integrations | Platform identifiers, permissions, content and insight data | Performance of the requested service; consent where required; legitimate interests in managing authorized business channels |
| Protect websites, systems, and users | IP address, logs, request metadata, security reports | Legitimate interests in security, fraud prevention, and service integrity; legal obligations where applicable |
| Meet accounting, tax, sanctions, and legal requirements | Company, transaction, invoice, and due-diligence records | Legal obligations; establishment or defense of legal claims |
| Optional analytics or marketing | Consent choices, device or campaign data where enabled | Consent where required by applicable law |
When processing relies on legitimate interests, we consider the necessity of the activity, the impact on the individual, and reasonable expectations. You may object as described under Your rights.
We do not use the information covered by this notice to make a decision based solely on automated processing that produces legal or similarly significant effects.
Meta platform data
This section applies when an individual or authorized business administrator connects, authorizes, or interacts with the Lornez Group Business Management application through Facebook, Instagram, or Threads.
Data that may be received
Depending on the feature used, the permissions approved, and the Meta product involved, we may receive:
- An app-scoped user identifier and basic account information made available by the approved permission.
- Facebook Page, Instagram professional account, or Threads account identifiers and account metadata.
- Content, post, media, comment, message, mention, or publishing metadata only where the relevant feature and permission are used.
- Engagement, reach, insight, or performance information made available to an authorized business account.
- Permission status, authorization time, token status, and technical logs needed to maintain and secure the connection.
Lornez Group does not ask for or receive your Facebook, Instagram, or Threads password. Do not send passwords or access tokens by email.
How platform data is used
- To provide the integration or management feature you authorize.
- To publish, retrieve, organize, moderate, respond to, or measure content where the approved feature requires it.
- To maintain permissions, troubleshoot failures, prevent misuse, and keep an audit trail of administrative actions.
- To comply with Meta Platform Terms, applicable law, and valid deletion or rights requests.
Platform data is not sold. It is not used to build unrelated advertising profiles. We do not request permissions that are not needed for an implemented feature.
Meta independently processes information under its own terms and privacy policy. Your Meta account settings and permissions remain available through the relevant Meta product.
Recipients and transfers
Access is limited to people and service providers who need the information for an authorized purpose. Recipients may include:
- Authorized Lornez Group personnel and relevant group operating teams.
- Hosting, database, email, cybersecurity, professional-adviser, logistics, accounting, and business-system providers acting under appropriate terms.
- Meta where necessary to use, administer, secure, or comply with the applicable platform integration.
- Public authorities, courts, regulators, or professional advisers where disclosure is required or legally justified.
- A successor organization in a genuine corporate transaction, subject to appropriate confidentiality and legal safeguards.
Some providers or platform operations may involve countries outside the European Economic Area. Where European data-protection law requires a transfer mechanism, we rely on an adequacy decision, approved contractual safeguards such as Standard Contractual Clauses, or another lawful basis, together with supplementary measures where appropriate.
You may contact us for more information about safeguards relevant to your data.
Retention
We keep personal data only for as long as necessary for the purpose, required by law, or needed to establish, exercise, or defend legal claims. The following periods are our ordinary working limits:
| Record | Ordinary retention |
|---|---|
| Business inquiry with no resulting contract | Up to 3 years after the last substantive interaction, unless an earlier deletion or objection applies |
| Contract, order, invoice, and accounting records | The contract lifecycle and applicable statutory period, commonly up to 10 years for accounting evidence |
| Website and security logs | Normally up to 12 months, with shorter operational logs where practical and longer retention only for an incident or claim |
| Meta authorization tokens | Until expiry, revocation, disconnection, or loss of the operational need |
| Meta app-scoped data | While the authorized integration is active; deletion is initiated after disconnection or a valid request and normally completed within 30 days, subject to lawful exceptions |
| Privacy and deletion request records | As needed to complete the request and demonstrate compliance, normally up to 3 years after closure |
Backups may retain residual copies for a limited rotation period. Such copies remain protected, are not restored for ordinary use, and are overwritten under the applicable backup schedule.
Your rights
Depending on the processing and applicable law, you may have the right to:
- Obtain information and access a copy of your personal data.
- Correct inaccurate or incomplete data.
- Request deletion where the legal conditions are met.
- Restrict processing in specified circumstances.
- Object to processing based on legitimate interests.
- Object at any time to direct marketing based on your personal data.
- Receive certain data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Withdraw consent at any time where processing relies on consent, without affecting prior lawful processing.
Send a request to lornez@lornez.com with the subject Privacy Request. Describe the service, website, account, or communication involved. We may request proportionate information to verify identity and protect data from unauthorized disclosure.
For Meta-connected data, use the dedicated Data Deletion Instructions.
You may lodge a complaint with the French data-protection authority, the CNIL, or another competent supervisory authority. We encourage you to contact us first so we can review the issue promptly.
Security
We use organizational and technical measures selected for the nature of the data and the relevant risk. These include, as appropriate:
- Encrypted transport for public websites and database traffic.
- Role-based access, dedicated service boundaries, restricted administrative access, and least-privilege database permissions.
- Separation of public website files, runtime configuration, and protected inquiry records.
- Logging, security review, backup controls, vulnerability response, and credential rotation procedures.
- Service-provider review and confidentiality or processing terms where appropriate.
No system can be guaranteed absolutely secure. If you believe you have found a vulnerability, use our responsible disclosure channel.
Contact and changes
Privacy questions and rights requests may be sent to:
LORNEZ GROUP
36 rue Scheffer, 75016 Paris, France
Email: lornez@lornez.com
This notice may be updated when services, platform permissions, legal requirements, providers, or processing practices change. The effective date appears at the top of the page. Material changes will be communicated through an appropriate channel where required.
