Privacy Policy

Introduction:

As part of its business activities, LSPA (LOVE'N SPA), through its website https://lovenspa.fr (hereinafter the "Site"), collects and processes personal data to provide information and services to its customers.

This privacy policy is intended to govern the processing of personal data carried out by LSPA (LOVE'N SPA).

Based in France, LSPA is committed to complying with the legislation and regulations in force concerning personal data protection and, more particularly:

  • EU Regulation 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data (GDPR);

 

  • the French Data Protection Act (Loi Informatique et Libertés) and Ordinance n°2018-1125 of December 12, 2018, relating to the protection of personal data, amending Law 78-17 of January 6, 1978, relating to data processing, files, and freedoms, and various provisions concerning the protection of personal data;

 

Thus, in accordance with current regulations, the data controller undertakes to process the personal data of its users fairly, lawfully, and transparently for specified, explicit, and legitimate purposes.

  1. Definitions

 

Personal data, hereinafter referred to as "Personal Data," is defined according to Article 4(1) of the GDPR as any information relating to an identified or identifiable natural person.

Personal data processing, hereinafter referred to as "Processing," is defined in Article 4(2) of the GDPR as any operation or set of operations performed using automated processes and applied to data or sets of data, such as collection, recording, storage, consultation, and use.

A User is designated, within the meaning of Article 4(1) of the GDPR, as a natural person who can be identified, directly or indirectly, in particular by reference to an identifier, such as a name, an identification number, or an online identifier.

By "Data Controller," we mean any legal or natural person who determines the purposes and means of Processing, i.e., the objective and how to achieve it.

By "Processor," we mean any legal or natural person who processes Personal Data on behalf of and for the Data Controller.

 

By "Third Party," we mean any legal or natural person not acting on behalf of the Data Controller.

 

  1. Who is responsible for processing the collected data?

 

The company LSPA (LOVE'N SPA) acts as the data controller in the collection and processing of personal data.

The registered office of the company LOVE'N SPA, a simplified joint-stock company, is located at 78 Avenue des Champs Élysée, 75008 Paris. The company is registered with the Paris Trade and Companies Register under number 898 917 604.

As data controller, LOVE'N SPA ensures a high level of protection of the Personal Data of data subjects at all stages of processing (collection, storage, destruction, etc.).

  1. Data subjects

 

The persons whose Personal Data is processed by LOVE'N SPA are as follows:

 

  • visitors to the Site;
  • Travelers, i.e., persons booking accommodation via the Site;
  • Hosts, i.e., persons listing accommodation for rent on the Site.

 

(hereinafter referred to as "Data Subjects").

 

  1. What data is collected and for what purpose?

 

During your interactions with LOVE'N SPA and as a User, you may be asked to provide information about yourself. In accordance with the principle of minimization and privacy by design, only the data necessary to achieve the following purposes are collected:

Data you provide directly:

  • Identification data, namely, name, first name, phone number, email, and postal code to address your contact requests to LOVE'N SPA;
  • Data necessary for booking accommodation;
  • Data necessary for listing accommodation (address, location, photographs, etc.);
  • Any other information you wish to bring to the attention of LOVE'N SPA.

 

Data we collect during our business relationship:

  • Billing data, namely, name, first name, postal address, phone number;
  • Financial transaction data, for payment and to fulfill contractual obligations, encrypted information related to the payment method as well as data necessary for delivery may be collected;

 

Data we collect automatically:

  • Browsing data and in particular automatically collected cookies, whether technical cookies necessary for browsing the website, statistical cookies, and, based on consent, cookies for redirection to our social networks.

 

  1. For what purposes and on what legal basis?

 

Under the principle of data minimization set out in Article 5 c) of the GDPR, only data necessary to achieve pre-defined objectives are collected. Thus, personal data processing is established for the following purposes:

  • Listing a Host's advertisement;

 

  • Managing payments for Travelers and Hosts;

 

  • Collecting cookies based on consent (Article 6 (1)(a) of the GDPR);

 

  • Performance of contractual and pre-contractual obligations (Article 6(1)(c) of the GDPR);

 

  • Legitimate interest: LOVE'N SPA may collect Personal Data for legitimate interest purposes such as improving services, transaction security, or commercial prospecting. You can object to the Processing of your Personal Data on this basis at any time.

 

  • Consent: in certain circumstances, particularly when the aforementioned legal bases are not applicable, LOVE'N SPA is required to obtain your explicit prior consent to the Processing of your Personal Data. In this case, you may withdraw your consent at any time.

 

  1. How long is the data stored?

 

According to Article 5 d) of the GDPR, personal data collected and processed for the aforementioned purposes is stored for a limited period and strictly necessary for the achievement of the intended objectives.

Data concerned

Purposes

Retention period

Identification data

Respond to your request

Accommodation booking

Accommodation listing

3 years from the last contact with the User

Data related to financial transactions and contact details

Performance of contractual obligations and login to the personalized area

Duration of the contract plus the applicable limitation period

Billing data

Prepare quotes and invoices

10 years

Browsing data

Cookie collection during website navigation

13 months from collection

 

  1. What types of measures are taken to protect data security, integrity, and confidentiality?

 

LOVE'N SPA undertakes to take all technical and organizational measures to ensure the protection and security of Personal Data, particularly against any loss, alteration, dissemination, or illegal use.

LOVE'N SPA ensures that such measures are implemented across all operations carried out as part of its processing activities, including during the collection, storage, and hosting of Personal Data.

In this regard, LOVE'N SPA also ensures that third parties it may use (technical service providers, suppliers, etc.) comply with this requirement to protect User Personal Data by implementing appropriate measures, in accordance with the GDPR. The technical and organizational measures implemented may include the use of secure registration forms, encryption, and/or restricted access to Personal Data.

LOVE'N SPA advises you to exercise the utmost caution in communicating your Personal Data, as well as your personal identifiers and passwords for accessing the site, to third parties.

Some messages or solicitations received may originate from malicious individuals attempting to obtain personal information about the User for fraudulent use (phishing). If the User receives a message that appears to be a phishing attempt, they are advised not to respond to it and not to open any attachments, images, or links contained in the message.

  1. Which subcontractors do we use?

 

As part of its commercial activity, LOVE'N SPA may use subcontractors for whom it undertakes to maintain an adequate level of protection. LOVE'N SPA uses subcontractors for:

  • Maintaining website management
  • Exchanging emails with the User
  • Managing payments on the Site

 

As such, the subcontractors concerned may have access to the Data Subject's Personal Data and process it on behalf of LOVE'N SPA, according to the latter's instructions and in compliance with this Policy, as well as any appropriate security and confidentiality measures.

 

LOVE'N SPA will implement procedures ensuring that the subcontractors it authorizes to access Personal Data respect and preserve the confidentiality and security of Personal Data.

 

To this end, LOVE'N SPA undertakes to impose on its subcontractor(s) the same obligations as those set out in this Policy, so that the confidentiality, security, and integrity of the Data are respected, and so that said Data cannot be transferred or leased to a Third Party, whether free of charge or not, or used for purposes other than those defined in this Policy.

 

When these Subcontractors are located outside the European Union or in a country that does not have adequate regulations meeting the requirements of applicable privacy laws, including the General Data Protection Regulation and the French laws transposing it, LOVE'N SPA frames its contractual relationship with its Subcontractor(s) by adopting appropriate contractual arrangements.

 

  1. Data transfers outside the European Union

 

All transfers of personal data to subcontractors located outside the European Union, if any, are supervised and provide all appropriate guarantees, particularly through the European Commission's standard contractual clauses, which ensure an adequate level of protection and the safeguarding of your fundamental rights.

 

  1. What are the User's rights?

 

In accordance with the General Data Protection Regulation and the French laws transposing it, data subjects whose Personal Data is processed have rights allowing them to maintain control over the information concerning them.

  • Right to object:

 

The User may object to the Royal College's Processing of their Personal Data for a legitimate reason.

 

  • Right of access and rectification:

 

The User may request from the Royal College access to all information concerning them, its origin, and obtain a copy thereof.

 

Furthermore, the User may require the Royal College to rectify, update, or delete their Personal Data.

 

  • Right to data portability:

 

The User may request to receive their Personal Data, particularly for the purpose of reusing it and transmitting it to another Data Controller.

 

  • Right to restriction of Processing:

 

The User has the right to obtain from the Royal College the restriction of the Processing of their Personal Data, particularly when they contest the accuracy of said Data or when the Processing is unlawful.

 

  • Right to erasure of Data ("right to be forgotten"):

 

The User may request the Royal College to erase their Personal Data, and the Royal College is obliged to comply with this request when the Personal Data is no longer necessary for the purposes for which it was collected or when the Data Subject withdraws the consent on which the Processing was based.

 

  • Right to communication of post-mortem Data:

 

The User can provide instructions regarding the communication of their Personal Data after their death.

 

Furthermore, the User is informed that they can withdraw their consent to the Processing of their Personal Data at any time.

 

To do so, you must send your request, proving your identity (name, first name, personalized identifier) and send it to the following postal address: LOVE'N SPA, 78 Avenue des Champs Élysée, 75008 Paris or contact@lovenspa.fr.

In case of dispute, the data subject has the right to file a complaint directly with the competent supervisory authority (CNIL).

  1. Use of cookies

 

A cookie is a small computer file placed and read when browsing a website or mobile application, regardless of the type of device used (phone, computer, tablet, etc.).

Its purpose is to collect information about your browsing and to send you adapted content. Only the issuer of a cookie is likely to read the information contained therein, during its validity period.

The placement of non-strictly technical cookies is subject to obtaining your consent. To manage cookies as closely as possible to your wishes, we invite you to consider the purpose of the cookies, as specified below, at the time of setting.

The Website uses cookies for the following purposes:

  • Purely technical and necessary for the site's operation: these cookies allow the Site to function optimally and securely. They also allow certain choices to be remembered, if you wish (language, currency, location, etc.);
  • Social networks: to verify if you are connected to third-party services (Facebook, Twitter, Instagram, LinkedIn). The placement of these Cookies requires the prior and express consent of Users;
  • Advertising: these Cookies allow targeted advertising to be offered to Site Users. Like social network cookies, the placement of these cookies requires the User's prior and express consent;
  • Audience measurement: to track statistical data on Site traffic (i.e., how users use the Site and to improve the Site's services) and to help us measure and study the effectiveness of our online interactive content, its features, advertisements, and other communications. Like social network cookies, the placement of these cookies requires the User's prior and express consent.

 

Via these cookies, these third parties may collect and use your browsing data for their own purposes, in accordance with their privacy policy.

You can withdraw your consent, at any time, for the placement of cookies operated during your navigation on our Site.

  1. Modification of this policy

LOVE'N SPA reserves the right to modify this Policy, particularly when such a change is made necessary by the adoption of new texts.

 

In this event, Data Subjects will be notified of the changes by receiving an email at the email address provided when creating their Customer account.