Skip to content

Legal information

Privacy policy

Version 2026-06 last updated: June 2026

1. Data controller

The controller responsible for the data collected on this site is Isabelle Mellah. Full contact details are in the legal notice.

No Data Protection Officer (DPO) has been appointed at this stage; any question regarding your data may be sent to i.bessonmellah@gmail.com.

2. Data collected and purposes

2.1 Contact form / bespoke request

  • Title, first name, last name, email, telephone, address, message.
  • Purpose: to respond to your request.
  • Legal basis: performance of pre-contractual measures taken at your request (GDPR art. 6.1.b).
  • Retention period: 3 years from the last exchange.

2.2 Registration for a course, workshop or session

  • Identity, contact details, information related to the registration.
  • Purpose: managing the registration, educational communication, follow-up.
  • Legal basis: performance of the contract (GDPR art. 6.1.b).
  • Retention period: 3 years after the end of the relevant season, then accounting obligations (10 years).

2.3 Shop order

  • Identity, billing and delivery details, order content.
  • Purpose: order fulfilment, invoicing, after-sales service.
  • Legal basis: performance of the contract plus statutory accounting obligations.
  • Retention period: 10 years for accounting records (French Commercial Code).

2.4 Customer account creation

  • Identity, contact details, password (hashed, never in plain text).
  • Purpose: managing the account and order / registration history.
  • Legal basis: performance of the contract.
  • Retention period: until the account is deleted at your request.

2.5 Newsletter

  • Email, first name, language.
  • Purpose: sending the editorial newsletter (studio notes, news).
  • Legal basis: consent (GDPR art. 6.1.a).
  • Retention period: until you unsubscribe.

3. Recipients of the data

Your data is intended exclusively for Isabelle Mellah and her strictly necessary technical processors:

  • Lovable Cloud / Supabase — hosting of the database and authentication (EU).
  • Stripe — payment processing (Ireland / EU, transfers to the United States governed by appropriate safeguards).
  • Resend — sending transactional emails and the newsletter (EU / United States with contractual safeguards).
  • Cloudflare — content delivery and protection of the site.

No data is transferred, sold or rented to third parties for commercial purposes.

4. Transfers outside the European Union

Some processors (Stripe, Resend, Cloudflare) may process data from the United States. These transfers are governed by the European Commission's standard contractual clauses and, where applicable, by their adherence to the Data Privacy Framework.

5. Your rights

In accordance with the GDPR, you have the following rights:

  • right of access to your data;
  • right to rectification;
  • right to erasure ("right to be forgotten");
  • right to restriction of processing;
  • right to object;
  • right to data portability;
  • right to withdraw your consent at any time (newsletter, marketing);
  • right to set directives for the use of your data after death.

You may exercise these rights by writing to i.bessonmellah@gmail.com. A response will be provided within a maximum of one month.

You also have the right to lodge a complaint with the CNIL (www.cnil.fr).

6. Security

Data is stored in secure databases, encrypted at rest and in transit. Passwords are stored hashed. IP addresses are never stored in plain text; only a salted hash (anonymised) is kept for anti-spam and audit purposes.

7. Cookies

Details of the cookies used are available on the Cookies page.

8. Changes

This policy may be updated. The version in force is indicated at the top of the page.