Privacy Policy
This policy explains how Palladium Cookies SAS, as data controller, collects and processes personal data of visitors to palladium-cookies.com. It is distinct from the GDPR Art. 28 DPA which governs the processing of platform customers' data.
1.Data controller
Palladium Cookies SAS, whose full details are in the legal notice (/legal/mentions-legales). For any data-protection question: dpo@palladium-cookies.com.
2.Scope of this policy
This policy covers only data collected on palladium-cookies.com (prospect visitors, sales enquiries, contact forms, support, newsletter). It does not cover the processing of end-user data on our customers' sites — that data is governed by each site's own cookie policy generated by our platform.
3.Security
Data is hosted in the European Union (OVHcloud, France), encrypted in transit (TLS 1.3) and at rest (AES-256). Access is strictly need-to-know and logged. In case of a breach likely to affect your rights, you will be informed within the 72-hour deadline of GDPR Art. 33.
4.Recipients and subprocessors
Your data is never sold. It may be shared with our subprocessors (hosting, transactional email, support, payment) publicly listed at /legal/subprocessors. All operate in the EU; any non-EU transfers are framed by 2021 Standard Contractual Clauses.
5.Your rights
Per GDPR Art. 12-22, you have rights of access, rectification, erasure, restriction, objection and portability, plus the right to define post-mortem instructions. To exercise them, write to dpo@palladium-cookies.com. We acknowledge within 72 business hours and reply within the statutory one-month deadline. You also have the right to lodge a complaint with the CNIL (cnil.fr).
6.Marketing-site cookies
The palladium-cookies.com site itself uses its own Palladium consent banner. Details (cookies set, purposes, durations, withdrawal) are at /legal/cookies.