Sève
ProductThe evidenceThe ritual
Reserve
Legal

Privacy Policy

Issued pursuant to Articles 12 to 14 of Regulation (EU) 2016/679 (General Data Protection Regulation) and to Loi n° 78-17 of 6 January 1978 on information technology, data files and civil liberties, as amended.

Last updated 18 August 2026

1.Identity of the Controller

1.1The controller within the meaning of Article 4(7) GDPR is Sève, contactable at hello@sevecollagen.com (the "Controller", "we" or "us").

1.2The Controller is established in the territory of the European Union. Accordingly, and by operation of Article 3(1) GDPR, the Regulation governs all processing carried out in the context of the activities of that establishment, irrespective of the place of residence of the data subject and irrespective of whether the processing itself takes place in the Union.

1.3All requests relating to this Policy shall be addressed to hello@sevecollagen.com. The Controller has not appointed a data protection officer, no ground under Article 37(1) GDPR requiring such appointment being met.

2.Scope and Definitions

2.1This Policy applies to the website published at sevecollagen.com (the "Site") and to the sale of the goods offered on it (the "Products").

2.2The terms "personal data", "processing", "controller", "processor", "recipient" and "data subject" bear the meanings given to them in Article 4 GDPR. "Customer" means any natural person placing an order on the Site.

3.Categories of Data Processed

3.1No personal data is required in order to consult the Site. Personal data is collected only upon the placing of an order or upon correspondence addressed to the Controller.

3.2The following categories of data are processed:

  • Identification and contact data: surname, first name, email address, telephone number.
  • Delivery and billing data: postal delivery address and billing address.
  • Transaction data: order contents, quantity, amount paid, currency, order and payment reference numbers, and the outcome of the payment authorisation.
  • Payment instrument data: processed exclusively by the payment service provider identified at Article 5. The Controller receives only the payment brand, the final four digits of the instrument and the authorisation outcome. At no time does the Controller collect, transmit or store the full payment card number, expiry date or security code.
  • Technical connection data: IP address, user agent, date and time of request, and URL requested, recorded in the hosting provider server logs.
  • Local storage data: the contents of the shopping basket, retained in the browser local storage of the Customer terminal under the key seve-cart.

3.3No special category of personal data within the meaning of Article 9(1) GDPR is collected, and none is required in order to purchase the Products.

4.Purposes and Legal Bases

4.1Processing for the purposes of concluding the contract of sale, executing the order, effecting delivery and handling returns is necessary for the performance of a contract to which the data subject is party, within the meaning of Article 6(1)(b) GDPR.

4.2Processing for the purposes of the issuance and retention of accounting records and invoices is necessary for compliance with a legal obligation to which the Controller is subject, within the meaning of Article 6(1)(c) GDPR, in particular the obligation arising under Article L123-22 of the French Commercial Code.

4.3Processing for the purposes of the security and availability of the Site, the prevention and detection of fraud, and the handling of correspondence is necessary for the purposes of the legitimate interests pursued by the Controller, within the meaning of Article 6(1)(f) GDPR. The Controller has assessed that those interests are not overridden by the interests or fundamental rights and freedoms of the data subject, having regard to the limited nature of the data concerned and to the absence of any profiling.

4.4No processing is carried out for the purposes of behavioural advertising, audience measurement, profiling, or the enrichment or resale of data. The Controller operates no advertising identifier and no analytics tag on the Site.

5.Recipients and Processors

5.1Personal data is disclosed only to the recipients listed below, each acting as a processor within the meaning of Article 28 GDPR and bound by a written agreement satisfying Article 28(3), save where stated otherwise:

  • Stripe, Inc. and Stripe Payments Europe, Limited — payment initiation and processing, fraud prevention and issuance of transaction receipts. In respect of the prevention of fraud and of its regulatory obligations as a payment institution, Stripe acts as an independent controller under its own privacy policy.
  • Vercel, Inc. — hosting of the Site and execution of the server-side code processing orders.
  • Resend (Plus Five Five, Inc.) — transmission of the internal order notification addressed to the Controller.
  • 1&1 IONOS SE — domain name and electronic mail routing.
  • The fulfilment operator and the carrier engaged for a given order — order preparation, packing and delivery of the parcel.

5.2The Controller does not sell personal data, does not rent it, and does not share it for the purposes of cross-context behavioural advertising.

5.3Personal data may additionally be disclosed to a competent authority where the Controller is compelled to do so by a legally binding request.

6.Transfers to Third Countries

6.1Certain recipients identified at Article 5 are established in, or store data in, the United States of America. Such transfers constitute transfers to a third country within the meaning of Chapter V GDPR.

6.2Those transfers are carried out on the basis of the standard contractual clauses adopted by the European Commission pursuant to Article 46(2)(c) GDPR, on the basis of the EU-US Data Privacy Framework where the recipient is certified under it, or, in respect of the delivery address, on the ground set out at Article 49(1)(b) GDPR, the transfer being necessary for the performance of the contract.

6.3A copy of the safeguards relied upon may be obtained upon written request to the address given at Article 1.3.

7.Retention Periods

7.1Personal data is retained for no longer than is necessary for the purposes for which it is processed, in accordance with Article 5(1)(e) GDPR, and specifically:

  • Accounting records and invoices: ten years from the close of the financial year, pursuant to Article L123-22 of the French Commercial Code.
  • Order and delivery data used for customer relations: three years from the last transaction.
  • Correspondence: three years from the last exchange.
  • Server logs: twelve months from collection.
  • Local storage basket data: until deleted by the Customer or by the browser; this data is held on the Customer terminal and not on the Controller infrastructure.

8.Rights of the Data Subject

8.1The data subject holds the rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection (Article 21) GDPR, together with the right to give directives concerning the fate of personal data after death pursuant to Article 85 of Loi n° 78-17 of 6 January 1978.

8.2Those rights are exercised by written request to hello@sevecollagen.com. The Controller shall respond within one month of receipt, that period being extendable by two further months where required by the complexity or number of requests, pursuant to Article 12(3) GDPR. Proof of identity may be required where reasonable doubt exists as to the identity of the applicant.

8.3The right to erasure does not extend to data whose retention is required in order to comply with a legal obligation, in particular the accounting obligation referred to at Article 7.1.

8.4The data subject has the right to lodge a complaint with a supervisory authority pursuant to Article 77 GDPR, and in particular with the Commission Nationale de l Informatique et des Libertes (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.

9.Terminal Storage and Absence of Consent Banner

9.1The Site deposits no cookie and no tracer for the purposes of advertising, audience measurement or profiling.

9.2The sole item written to the Customer terminal is the shopping basket referred to at Article 3.2. That storage is strictly necessary for the provision of a service expressly requested by the user and accordingly falls within the exemption from consent provided at Article 5(3) of Directive 2002/58/EC and at Article 82 of Loi n° 78-17 of 6 January 1978. The absence of a consent banner on the Site is therefore deliberate and compliant, and does not constitute an omission.

10.Automated Decision-Making

10.1The Controller takes no decision based solely on automated processing producing legal effects concerning the data subject or similarly significantly affecting them, within the meaning of Article 22(1) GDPR.

10.2The payment service provider applies automated fraud-scoring to payment attempts. A refusal so arising may be reviewed upon request addressed to the Controller, who shall procure human intervention in the matter.

11.Provisions Applicable to United States Residents

11.1Residents of the State of California hold, under the California Consumer Privacy Act as amended by the California Privacy Rights Act (Cal. Civ. Code section 1798.100 et seq.), rights to know, to delete, to correct and to opt out of the sale or sharing of personal information, together with the right not to be subjected to discrimination for their exercise. Residents of other States having enacted comprehensive privacy legislation hold rights of equivalent scope.

11.2The Controller neither sells nor shares personal information, does not process it for targeted advertising, and does not engage in profiling in furtherance of decisions producing legal or similarly significant effects. The rights set out at Article 8 are extended to such residents on identical terms and are exercised by the same means.

12.Minors

12.1The Products are not intended for minors and the Site is not directed at them. The Controller does not knowingly collect personal data relating to persons under the age of sixteen. Any such data brought to its attention shall be erased without undue delay.

13.Security

13.1The Controller implements appropriate technical and organisational measures pursuant to Article 32 GDPR, including transport encryption of all communications with the Site, cryptographic verification of the authenticity of payment notifications, and the exclusion of payment instrument data from its own systems.

14.Amendment

14.1This Policy may be amended. The date of the version in force appears at the head of this page. Any amendment materially affecting orders already placed shall be notified individually by electronic mail.