Privacy policy
Last updated — 1 September 2026
Korean Street Market (KSM) attaches the highest importance to the protection of your personal data. This policy describes, in accordance with the General Data Protection Regulation (GDPR) and the amended French Data Protection Act, what data we collect, for what purposes, for how long, and what rights you have over it.
1. Data controller
The data controller is Korean Street Market — [legal form to be completed], with its registered office at [address to be completed], registered with the Paris Trade & Companies Register under number [to be completed].
Contact: privacy@koreanstreetmarket.com — Postal address: “Data Protection”, [address to be completed].
A Data Protection Officer (DPO) [is / is not] appointed. [If applicable: DPO — Full Name, dpo@koreanstreetmarket.com.]
2. Data collected
Data you provide directly: first and last name, email address, phone number, message, preferences (via newsletter, contact, membership, reservation, application forms).
Member account data: credentials, purchase history, loyalty points, dietary preferences (if you enter them).
Browsing data: IP address (masked at insertion — last IPv4 octet dropped, IPv6 /64 prefix kept), browser type, pages visited, referrer, timestamps, collected through cookies and similar technologies (see the Cookie Policy).
3. Purposes and legal bases
To respond to your contact requests and manage the commercial relationship — basis: performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR).
To send you our newsletter and marketing communications — basis: your consent (Art. 6(1)(a) GDPR), withdrawable at any time.
To manage your membership and the loyalty programme — basis: performance of the membership contract (Art. 6(1)(b) GDPR).
To measure site audience and improve the experience — basis: our legitimate interest (Art. 6(1)(f)) or your consent depending on the tool (see Cookie Policy).
To comply with our legal and accounting obligations — basis: legal obligation (Art. 6(1)(c) GDPR).
To prevent and detect fraud and abuse — basis: legitimate interest (Art. 6(1)(f) GDPR).
4. Recipients and processors
Your data is accessible to our internal teams in charge of customer relations, marketing, security and accounting, within the limits of their functions.
We use processors strictly bound by contract: hosting (Amazon Web Services — Europe/Paris region), transactional email (Amazon SES), newsletter campaign delivery ([provider to be completed — e.g. Brevo]), audience analysis ([provider to be completed — e.g. Plausible / Matomo]), payment processing ([provider to be completed]).
We never sell or rent your data. We share it with public authorities only where required by law.
5. Transfers outside the European Union
Our main infrastructure is located in the European Union. Some processors may need to process data outside the EU; in that case, transfers are governed by the European Commission’s Standard Contractual Clauses or by an adequacy decision.
6. Retention periods
Prospects and newsletter: until you withdraw consent, and no longer than 3 years from the last contact.
Customers and members: for the duration of the relationship, then in intermediate archiving for 5 years to meet civil and commercial obligations.
Invoicing and accounting: 10 years (Article L.123-22 of the French Commercial Code).
Connection logs and security data: 12 months maximum, in line with CNIL recommendations.
7. Your rights
Subject to conditions, you have the following rights over your data: access, rectification, erasure, objection, restriction, portability, withdrawal of consent, and definition of post-mortem directives.
To exercise these rights: write to privacy@koreanstreetmarket.com or by post to “Data Protection” — [address to be completed]. Proof of identity may be requested in case of reasonable doubt.
We commit to responding within one month, which may be extended to three months in complex cases.
You also have the right to lodge a complaint with the CNIL (French Data Protection Authority — www.cnil.fr).
8. Security
We implement technical and organisational measures to protect your data: TLS encryption in transit, at-rest encryption of backups, access management on a least-privilege basis, logging of sensitive access, regular reviews of processors.
No Internet transmission is entirely secure; in the event of a breach likely to result in a risk to your rights, we will notify the CNIL within 72 hours and inform you as soon as possible.
9. Changes
This policy may be updated. The date at the top of the page indicates the last revision. Substantial changes will be flagged with a banner on the site or by email.