Privacy Policy

Phytomisan France & Europe

Last updated: February 25, 2026

1. Identity of the data controller

The data controller for personal data collected on the website https://phytomisan.com/ is:

Phytomisan France & Europe

14, Rue de l'Ours, 68200 Mulhouse

Phone: +07.69.55.34.98

Email: contact@phytomisan.com

2. Personal data collected

We collect two categories of personal data on our site:

Data that you provide directly

When creating an account, placing an order or subscribing to our newsletter, we collect: name, surname, email address, postal address, telephone number and payment information.

Data collected automatically

During your browsing, we collect: IP address, browser type, pages visited, duration of visit and interactions with the site, via the cookies detailed in section 8.

3. Purposes of processing

Your personal data is used for:

  • Order management: processing, shipping, tracking and invoicing.
  • Customer service: answering your questions and after-sales support.
  • Marketing communication: sending newsletters and promotional offers (only with your prior consent).
  • Website improvement: traffic analysis and optimization of the user experience.
  • Fraud prevention: securing transactions and detecting suspicious activity.

4. Legal basis for processing

Each processing operation is based on a legal basis compliant with the General Data Protection Regulation (GDPR):

  • Execution of a contract (article 6.1.b): management and monitoring of your orders.
  • Consent (article 6.1.a): sending marketing communications and placing cookies that are not strictly necessary.
  • Legitimate interest (article 6.1.f): improvement of our services, fraud prevention and site security.

5. Recipients of the data

Your data may be transmitted to the following categories of recipients:

  • Payment providers: Stripe and/or PayPal, for the secure processing of your transactions.
  • Carriers: for shipping and tracking your orders.
  • Hosting provider: O2SWITCH (headquarters in France), which hosts the site's data.
  • Analytics and marketing tools: Google Analytics, Facebook (Meta) Pixel, Hotjar, Klaviyo — within the framework described in section 8.
  • Legal authorities: if required by law or to protect our rights.

6. Data transfers outside the European Union

Your data is hosted in France (O2SWITCH). However, some of our service providers (Google, Meta, Hotjar, Klaviyo) may transfer data to the United States. These transfers are governed by the EU-US Data Privacy Framework or by standard contractual clauses approved by the European Commission, in accordance with Articles 46 and 49 of the GDPR.

7. Shelf life

We retain your data for specific periods, in accordance with the recommendations of the CNIL:

Data categoryShelf life
Customer data (account, orders)3 years after the last purchase or contact
Prospect data (newsletter)3 years after the last active contact
Billing data10 years (accounting obligation, Commercial Code)
Analytics cookies13 months maximum
Connection logs12 months (LCEN obligation)

8. Cookies and trackers

In accordance with the CNIL guidelines of October 1, 2020, our website displays a consent banner on your first visit. You can accept or refuse each category of cookies. Only cookies strictly necessary for the website's operation are placed without your consent.

Here are the cookies and trackers used on phytomisan.com:

Cookie / ToolfinalityDurationType
Session cookiesHow the site works (shopping cart, login)SessionStrictly necessary
Google AnalyticsAnonymized attendance statistics13 monthsAnalysis (consent)
Facebook Pixel (Meta)Advertising performance measurement13 monthsMarketing (consent)
HotjarUser behavior analysis (heatmaps)12 monthsAnalysis (consent)
KlaviyoPersonalization of marketing emails12 monthsMarketing (consent)
Stripe / PayPalSecure paymentSessionStrictly necessary

You can change your preferences at any time via the "Manage cookies" link accessible in the footer of the site.

9. Your rights

In accordance with the GDPR (articles 15 to 22), you have the following rights:

  • Right of access: to obtain a copy of your personal data.
  • Right of rectification: to correct inaccurate or incomplete data.
  • Right to erasure: request the deletion of your data (under certain conditions).
  • Right to restriction: temporarily suspend the processing of your data.
  • Right to object: to refuse the processing of your data for legitimate reasons.
  • Right to data portability: to receive your data in a structured and machine-readable format.
  • Right to withdraw consent: withdraw your consent at any time for processing based on it.

To exercise your rights, contact us at: contact@phytomisan.com

We will respond within a maximum of 30 days. In the case of a complex request, this period may be extended by an additional two months (we will inform you of this).

10. Complaint to the CNIL

If you believe that the processing of your personal data does not comply with regulations, you have the right to lodge a complaint with the National Commission for Information Technology and Civil Liberties (CNIL):

CNIL — 3, Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07

Website: https://www.cnil.fr

11. Data security

We implement technical and organizational measures to protect your data: SSL/TLS encryption of exchanges, restricted access to data, secure hosting in France (O2SWITCH), and regular backups.

12. Changes to this policy

We may modify this policy at any time. The update date at the top of the document indicates the latest revision. In the event of a substantial change, we will notify you by email or by posting a notification on the website.

13. Contact

For any questions relating to this policy or the processing of your data:

Phytomisan France & Europe

14, Rue de l'Ours, 68200 Mulhouse

Email: contact@phytomisan.com

Phone: +07.69.55.34.98

Cart