Privacy policy

MOLOKOY (the "Data Controller") uses this policy to inform users of its application (the "Users") about the processing of personal data collected through the application available from https://renforun.com (the "Application").

1. Who is involved?

MOLOKOY

5 rue de la Carierette, 34160 ST DREZERY, France

Represented by Mr Jean-Yves ZINSOU

2. What personal data is collected, and when?

The data controller may collect the following data:

  • User identification data, such as name, first name, username, and date of birth.
  • Connection data, such as IP address and country of connection.

This data may be collected when the user:

  • accesses the application;
  • subscribes to the application;
  • creates or updates a customer account;
  • contacts customer support.

Mandatory or optional fields are indicated to the user when data is collected by an asterisk (*). Providing mandatory data may be a regulatory or contractual requirement, or may be necessary to access the services. Access to the Application services cannot be granted if this information is not provided. By voluntarily providing optional personal data, the User expressly agrees that it may be processed under the conditions and for all the purposes described below.

3. Cookies and social networks

3.1. Cookies

Operational browsing on the Application requires the use of cookies, which are small tracking files placed on the User's device and which give the Data Controller access to standard connection information. Cookies may be used for several purposes, such as remembering a customer identifier, current cart contents, or an identifier used to track browsing for statistical or advertising purposes.

All collected information is used only to monitor the volume, type, and configuration of traffic using the Application, to improve the design and layout of the Application, and more generally to improve the service provided by the Data Controller.

The Data Controller uses cookies provided and stored by Google LLC, located in the United States. For more information, Users may consult Google's privacy information page: https://policies.google.com/technologies/types.

Google Analytics counts Users and identifies how they use the Application. These cookies are placed and read on Users' devices when they agree to receive them. The data generated by these cookies relates to use of the Application and the Users' country of connection through collection of shortened IP addresses. This data is immediately anonymized by Google Analytics and is not disclosed to the Data Controller. The Data Controller cannot identify a natural person through this process.

The Data Controller recommends accepting these cookies to make browsing the Application easier. Users who wish to refuse cookies may configure cookies individually or globally, or systematically refuse them through their browser settings. The Data Controller reminds Users that refusing all cookies may prevent them from using part of the Application services.

The personal data collected through cookies (cookie identifier) is kept by the Data Controller for 13 months. It is not transferred to third parties or used for purposes other than those described here.

3.2. Social networks

The Data Controller is present on several social networks, including Facebook, Instagram, and LinkedIn. In this context, the Data Controller may process public profile data of social network users who share, subscribe, follow, or contact the Data Controller on those platforms.

The Data Controller cannot be held responsible for the User's public data that is accessible on these networks and platforms. Users are advised to read the privacy policies that apply to each platform in order to configure their privacy settings.

4. For what purposes?

The Data Controller processes the User's personal data for the following purposes:

  • Sending newsletters by electronic communication to Users;
  • Performing and billing subscriptions on the Application;
  • Responding to the User's requests and information inquiries about the services offered by the Data Controller;
  • Preparing commercial statistics;
  • Carrying out audience measurement, including page views, visits to the Application, User activity, and return frequency;
  • Participation in games, contests, or promotional operations;
  • Provision by third parties of technical, logistical, or other functions on behalf of the Data Controller;
  • Personalizing the services offered;
  • Managing access, rectification, and objection rights requests;
  • Debt recovery and exercise of any legal rights by the Data Controller.

If the User's personal data is processed for different purposes, the Data Controller undertakes to inform the User and, where required by law, to obtain prior consent.

5. On what legal bases?

Users' personal data is processed by the Data Controller in accordance with applicable regulations, in particular:

  • when the User has given free, specific, informed, and unambiguous consent to the processing of their data, such as for information requests, newsletter registration, or cookie use;
  • when processing is necessary for performance of a contract in connection with the User's subscription;
  • when processing is necessary for compliance with the Data Controller's legal or regulatory obligations, such as fraud prevention;
  • when justified by the Data Controller's legitimate interests, such as security measures or operation of the Application;
  • when necessary for the establishment, exercise, or defense of the Data Controller's legal claims, such as debt recovery or civil or criminal liability proceedings.

6. Personal data and profiling

The Data Controller does not carry out profiling activities using the data processed under this policy.

7. Who receives the User's personal data?

The Data Controller discloses collected data to technical providers responsible for hosting its IT system and the Application, as well as providers responsible for online payment, marketing, sales, legal, litigation, accounting, and User relationship services, only for the purposes mentioned above and within the limits necessary for the tasks assigned to them.

These recipients may contact the User directly using the contact details provided by the User.

The Data Controller requires these recipients to use the User's personal data only to manage the services for which they are responsible and in accordance with applicable personal data protection laws and regulations.

Where applicable, the User's personal data may be disclosed to third parties authorized by law, in particular following an express and reasoned request from judicial authorities.

If the Data Controller is involved in a merger, acquisition, asset sale, or judicial reorganization procedure, it may transfer or share all or part of its assets, including the User's personal data. In that case, the User will be informed before any transfer of personal data to a third party.

Finally, with the User's express authorization, the Data Controller reserves the right to use Users' personal data directly or indirectly, for example by transmitting it to partners, for commercial prospecting purposes.

8. How is the User's personal data stored, and is it transferred outside the European Union?

The User's personal data is stored within the European Union in the databases of the Data Controller or its providers.

However, some of the User's personal data may be processed by providers established in a third country that does not offer equivalent personal data protection guarantees, such as the United States. In this respect, the Data Controller has entered into agreements with these providers that comply with the standard data protection clauses adopted by the European Commission. These clauses may be provided to Users upon request.

9. How is the User's personal data protected?

The Data Controller implements organizational, technical, software, and physical digital security measures to protect the User's personal data against alteration, destruction, and unauthorized access. However, the internet is not a completely secure environment and the Data Controller cannot guarantee the security of transmission or storage of the User's data on the internet.

10. How long is the User's personal data kept?

Data is kept in accordance with the law for a period justified by the purpose of the processing and, in any event, for the applicable statutory retention periods.

11. What rights does the User have?

In accordance with Regulation (EU) 2016/679 of 27 April 2016 and French Law no. 78-17 of 6 January 1978, as amended, the Data Controller clearly and fully informs the User of their rights. If the User has further questions, the Data Controller's dedicated service remains available to guide the User and provide useful information to preserve those rights.

The User has:

  • a right of access to their data, including confirmation of whether their data is processed, a copy of their data, and information on the characteristics of the processing carried out by the Data Controller;
  • a right to rectification of inaccurate or incomplete data;
  • a right to erasure of data no longer necessary for processing, a right to withdraw consent, a right to object to processing where there are no compelling legitimate grounds, and a right to object to commercial prospecting;
  • a right to restriction of processing where data accuracy is being verified, or where data is only necessary for the exercise of legal claims;
  • a right to data portability, to request transmission to another controller of data provided with consent or in connection with the contract;
  • a right not to be subject to a decision based exclusively on automated processing that produces significant legal effects concerning the User;
  • a right to define instructions concerning the fate of their data after death.

The User may exercise these rights at any time with the Data Controller:

  • by post to the following address:

MOLOKOY

5 rue de la Carierette

34160 ST DREZERY, France

The User must specify in the request their surname, first name, and the email or postal address to which they would like the Data Controller's response to be sent.

For security reasons and to prevent fraudulent requests, the request must be accompanied by proof of identity. This proof will be destroyed after the request has been processed.

In accordance with the law, the request will receive a response within one month of receipt.

Finally, the User has the right to lodge a complaint with the CNIL or any other competent supervisory authority in their country of residence.

The User may submit this complaint to the French CNIL:

  • by post to:

3 Place de Fontenoy

TSA 80715

75334 PARIS CEDEX 07, France

  • by telephone at +33 1 53 73 22 22, Monday to Thursday from 9:00 to 18:30 and Friday from 9:00 to 18:00;
  • by fax at +33 1 53 73 22 00;
  • via the CNIL website at: https://www.cnil.fr/fr/plaintes.