In effect as of March 1, 2026
This Privacy Policy is intended to inform users of the inkora.art website about how their personal data is collected, processed, and protected, in accordance with Regulation (EU) 2016/679 of April 27, 2016 (GDPR) and amended French law n°78-17 of January 6, 1978.
1. Data controller
The controller responsible for processing personal data is:
- Raison sociale : Inkora (EI)
- Manager: BROU Diambra
- SIRET : 823 642 558 00048
- Adresse : Meudon
- Phone: +33 6 65 33 90 86
- Email : contact@inkora.art
2. Data collected
We collect the following categories of personal data:
When placing an order:
- First and last name
- Billing and shipping address
- Adresse email
- Phone number
- Order history
When creating an account:
- First and last name
- Adresse email
- Password (encrypted)
- Adresse postale
While browsing:
- Adresse IP
- Browser type and operating system
- Pages visited and time spent browsing
- Cookies (see dedicated section)
When using the contact form:
- Name, email address, message content
Paiement : payment data is processed exclusively by Stripe and is never stored by Inkora.
3. Purposes of processing
- Order management: processing, production, shipping, tracking, and after-sales service
- Customer account management: account creation, login, purchase history
- Communication : responding to your requests (only with consent for the newsletter)
- Site improvement: traffic statistics (anonymized data)
- Legal obligations: retention of invoices and accounting records
4. Legal basis for processing
- Performance of the contract (Article 6.1.b GDPR): processing your order
- Consentement (Article 6.1.a GDPR): non-essential cookies, newsletter
- Legitimate interest (Article 6.1.f GDPR): site improvement, fraud prevention
- Legal obligation (Article 6.1.c GDPR): retention of billing data
5. Recipients of data
Your personal data may be shared with the following recipients, strictly within the scope of the purposes mentioned above:
| Destinataire | Purpose | Localisation |
|---|---|---|
| Printify (Printify OÜ) | Order production and shipping | Lettonie (UE) / prestataires internationaux |
| Stripe | Secure payment processing | EU / United States (standard contractual clauses) |
| Transporteurs | Package delivery | UE / International |
| Hostinger International Ltd | Website hosting | Chypre (hostinger.fr) |
| Google Analytics | Traffic statistics (anonymized IP) | With consent |
We never sell, rent, or share your personal data with third parties for commercial purposes.
6. Transfers outside the European Union
Some of our processors (Printify, Stripe) may transfer data outside the European Union. These transfers are governed by standard contractual clauses approved by the European Commission or by other adequate protection mechanisms in accordance with the GDPR.
7. Retention period
| Data type | Duration |
|---|---|
| Order data | 5 ans (obligation comptable) |
| Compte client | 3 years after the last activity |
| Billing data | 10 years (legal obligation) |
| Browsing data (cookies) | 13 mois maximum |
| Formulaire de contact | 3 years after the last contact |
8. Your rights
Under the GDPR, you have the following rights:
- Right of access (Article 15): obtain a copy of your data
- Droit de rectification (Article 16): correct your inaccurate data
- Right to erasure (Article 17): request deletion of your data
- Right to restriction of processing (article 18)
- Right to data portability (Article 20): receive your data in a structured format
- Droit d’opposition (article 21)
- Right to withdraw your consent at any time
To exercise your rights: contact@inkora.art
Response within 30 days. Proof of identity may be requested.
Complaint to the CNIL (French data protection authority): www.cnil.fr — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
9. Cookies
Essential cookies (no consent required):
- Shopping cart and WooCommerce session
- Cookie preferences
Analytics cookies (with consent):
- Audience measurement (Google Analytics, anonymized IP)
You can manage your preferences via the consent banner at the bottom of the page.
10. Data security
- SSL/TLS encryption for all communications
- Secure payments via Stripe (PCI-DSS certified)
- Restricted data access (authorized staff only)
- Encrypted passwords (hashing)
- Regular, secure backups
11. Updates
This policy may be amended at any time. The date of the last update is shown below.
Last updated: March 2026