Privacy Policy
This Privacy Policy is intended to inform users of the aurea-logica.com website about how their personal data is collected and processed when using the website and purchasing digital content.
This policy has been prepared in accordance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of personal data (the GDPR), as well as the French Data Protection Act (Loi Informatique et Libertés).
1. Data Controller
The data controller responsible for the personal data collected in connection with the website is:

Contact email address for the website and requests relating to personal data:
contact@aurea-logica.fr2. Personal Data Collected
In connection with the sale of digital content, the following data may be collected:
Identification Data
- last name;
- first name;
- email address;
- postal address.
This information may be provided during the payment process in order to process the order and issue the invoice, in particular.
Order Data
We may also process:
- order ID;
- Stripe payment session ID;
- order contents;
- version of the purchased product;
- format of the purchased digital content;
- order date;
- download-related information;
- information necessary for technical order tracking.
Payment Data
Bank payment data is processed directly by Stripe.
The website does not store complete payment card numbers or card security codes.
Stripe acts, in particular, as a payment and billing service provider for transactions carried out on the website.
3. Purposes of Processing
Personal data is used solely for the following purposes.
Order Processing and Fulfilment
Data is used to:
- process and confirm orders;
- enable payment;
- provide purchased digital content;
- generate and send communications necessary for order fulfilment;
- manage downloads;
- provide technical order tracking.
The legal basis for this processing is the performance of the contract entered into with the customer.
Billing and Accounting and Tax Obligations
Certain data is processed in order to:
- issue invoices;
- retain information necessary for accounting;
- comply with applicable tax and accounting obligations;
- provide evidence of commercial transactions.
The legal basis for this processing is compliance with a legal obligation.
Invoices are generated and managed in particular by Stripe in accordance with the seller's Stripe account configuration.
Data required for accounting obligations may be retained for the periods required by applicable regulations. In particular, accounting records supporting transactions may need to be retained for 10 years. The French Data Protection Authority (CNIL) also indicates that data necessary for order management and billing may be retained for up to 10 years for accounting purposes.
Security and Prevention of Fraudulent Use
Certain technical data relating to orders and downloads may be used to:
- secure the distribution of digital content;
- prevent fraudulent use;
- detect or prevent abnormal use of the service;
- ensure the integrity of orders and distributed files.
This processing is based on the legitimate interest of the data controller in ensuring the security of its business and services.
4. Mandatory Nature of the Data
Information requested during the ordering process is necessary to complete the sale when it is essential for payment, billing or delivery of the digital content.
Refusal to provide the necessary information may prevent the order from being completed.
Information that is not necessary for these purposes is not requested.
This approach is consistent with the principle of data minimization under the GDPR: only data necessary for the intended purpose should be collected.
5. Data Recipients
Personal data may be accessible, according to their respective needs, to the following categories of recipients:
Guillaume Borg EI
The data controller may access data necessary for order management, billing, customer support and compliance with legal obligations.
Stripe
Stripe processes data necessary, in particular, for:
- payment;
- fraud prevention;
- billing;
- management of tax information;
- sending invoices and receipts where applicable.
Payment-related information is processed by Stripe in accordance with its own policies and terms.
Cloudflare
Cloudflare services are used for the website's technical infrastructure.
They may be involved in the technical processing of data necessary for the operation of:
- the website;
- the Worker;
- the database used to manage orders;
- digital content storage;
- file distribution.
Email Delivery Services
Technical service providers may be used to send transactional emails necessary for order fulfilment, including to deliver digital content or information relating to the order.
These providers use the data only to the extent necessary to provide their services.
6. Data Retention
Personal data is not retained indefinitely.
The retention period depends on the purpose of the processing and the applicable legal obligations. The CNIL reminds that retention periods must be determined according to the purpose pursued and that indefinite retention is not permitted.
Order Data
Data necessary for the operation and monitoring of orders is retained for as long as necessary to manage them.
Once no longer necessary for routine management, certain data may be archived where a legal, accounting or tax obligation, or the need to defend the rights of the data controller, justifies such retention.
Billing Data
Data necessary for billing and accounting obligations is retained for the period required by applicable regulations, including 10 years for the relevant accounting records.
Data Necessary for Download Management
Technical information necessary to deliver and secure downloads is retained for as long as necessary for this purpose.
Data that is no longer necessary is deleted or anonymized, subject to applicable legal obligations.
7. No User Account
The website does not require the creation of a user account.
Purchases are made directly through the payment process provided by Stripe.
There is therefore no permanent customer account to maintain and no user profile intended to track the customer's activity on the website.
8. Email Communications
The email address provided when placing an order may be used to send communications strictly necessary for its fulfilment, including:
- order confirmation;
- invoice or receipt;
- payment-related information;
- link or access to purchased digital content;
- information necessary for after-sales service.
These communications do not constitute commercial marketing: they are necessary for the fulfilment of the order.
No newsletter or commercial marketing is currently sent in connection with the website.
9. Cookies and Similar Technologies
The website currently does not use advertising cookies, audience measurement cookies or behavioral tracking devices intended to create user profiles.
However, the website may use technical mechanisms that are strictly necessary for its operation, including those necessary for security, displaying the website or processing an order.
These technical mechanisms are not used for advertising targeting or to create a commercial profile of visitors.
A specific cookie policy may provide further details if new services or technologies are added to the website.
10. Transfers of Data Outside the European Union
Certain technical service providers used to operate the website, including international providers such as Stripe or Cloudflare, may process certain data from countries outside the European Economic Area or allow certain entities within their group or their subcontractors to access such data from those countries.
Where such transfers are necessary, they are carried out in accordance with the requirements of the GDPR and applicable transfer mechanisms, such as an adequacy decision by the European Commission or appropriate safeguards where required.
The data controller does not directly transfer personal data to third parties for commercial or advertising purposes.
The GDPR requires, in particular, that data subjects be informed of the possible existence of transfers to third countries and the safeguards associated with them.
11. Data Security
Appropriate technical and organizational measures are implemented to protect personal data against:
- unauthorized access;
- loss;
- destruction;
- unauthorized modification;
- unauthorized disclosure.
The technical infrastructure relies in particular on Cloudflare services for website operation, storage and processing of data necessary for the operation of the service.
Access to administrative services and data is restricted to persons and services that require such access.
As no security measure can guarantee absolute protection, the data controller strives to maintain a level of security appropriate to the risks associated with the processing carried out.
12. Your Rights
In accordance with the GDPR, depending on the circumstances and the conditions provided for by applicable regulations, you have the following rights:
Right of Access
You may request confirmation as to whether personal data concerning you is being processed and, where applicable, obtain a copy of the relevant data.
Right to Rectification
You may request the correction of inaccurate or incomplete personal data.
Right to Erasure
You may request the deletion of your personal data where the conditions provided for by the GDPR are met.
This right may nevertheless be limited where retention of the data is necessary to comply with a legal obligation, particularly accounting and tax obligations, or for the establishment, exercise or defense of legal claims.
Right to Restriction of Processing
You may request restriction of the processing of your data in the situations provided for by the GDPR.
Right to Object
You may object to certain processing based on legitimate interests, subject to the conditions provided for by the GDPR.
Right to Data Portability
Where the legal conditions are met, you may request to receive the personal data you have provided in a structured, commonly used and machine-readable format.
These rights are provided for, in particular, by the GDPR and must be exercisable with the data controller.
13. How to Exercise Your Rights
To exercise your rights or for any questions concerning the processing of your personal data, you may contact:
contact@aurea-logica.frIn order to protect personal data and prevent an unauthorized person from obtaining information concerning another person, information allowing the applicant's identity to be reasonably verified may be requested where necessary.
Where possible, the request should specify:
- your name;
- the email address used for your order;
- the purpose of your request;
- the information or processing concerned.
Requests are processed within the time limits provided for by the GDPR.
In principle, a response must be provided within one month. This period may be extended by two months where the request is complex, provided that the data subject is informed of the extension.
14. Complaint to the CNIL
If, after contacting us, you believe that your rights regarding your personal data have not been respected, you may lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL).
The CNIL is the French supervisory authority responsible for the protection of personal data.
15. Changes to This Privacy Policy
This Privacy Policy may be updated to take into account:
- changes to the website;
- changes to the services offered;
- changes to data processing activities;
- changes in laws and regulations.
The applicable version is the version published on the website at the time of consultation.
The date of the latest update is shown at the top of this Privacy Policy.