Privacy policy
28/09/2026
This translation is provided for convenience; in case of discrepancy, the French version prevails. This policy explains how Sema Photographie processes your personal data on semaphotographie.fr, in accordance with the GDPR (EU Regulation 2016/679).
Data controller
Sema Photographie, sole proprietorship, SIREN 931 365 068, 15 rue de l'École, 67800 Bischheim, France. Contact: contact@semaphotographie.fr.
Data we collect
- Identification and contact details: name, e-mail, phone, postal address (contact, appointment and order forms).
- Photographs: the photos taken during your session, stored in private, code-protected galleries.
- Order and payment data: selected products, amounts, payment reference. Card details are entered directly with Stripe and never pass through our servers.
- Technical data: IP address, browser (user-agent) and language, logged when galleries and delivery links are accessed, for security purposes.
Purposes and legal bases
- Providing the service (galleries, selection, orders, delivery) — performance of the contract (art. 6(1)(b) GDPR).
- Answering contact and appointment requests — pre-contractual measures (art. 6(1)(b)).
- Invoicing and accounting obligations — legal obligation (art. 6(1)(c)).
- Security and fraud prevention (access logs, rate limiting) — legitimate interest (art. 6(1)(f)).
Retention periods
- Galleries and photos: until the client session expires, then deleted; earlier deletion on request.
- Order data: at most 45 days after product delivery, except accounting records and invoices kept for 10 years (legal obligation).
- Contact messages and appointments: for the time needed to handle the request.
- Technical logs (IP address): 12 months at most, in line with CNIL guidance.
Recipients and processors
Data is processed by the following processors, strictly for the purposes above:
- MongoDB Atlas (MongoDB, Inc.) — database hosting
- Google Firebase Storage (Google LLC / Google Ireland Ltd) — photo storage
- Stripe (Stripe, Inc. / Stripe Payments Europe Ltd) — card payment processing
- Resend (Resend, Inc.) — transactional e-mails
- Amazon Web Services (AWS EMEA SARL) — website hosting
Transfers outside the EU
Some processors (Stripe, Resend, Google) may process data in the United States. These transfers are covered by the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.
Cookies and local storage
The site uses no advertising cookies and no audience analytics. Only strictly necessary items are set:
- client_access: session cookie keeping you signed in to your gallery for 2 hours.
- Stripe cookies (__stripe_mid, __stripe_sid): set only if you choose card payment, for security and fraud prevention.
- Browser local storage: order form draft (cleared after 24 hours), image display cache (24 hours) and interface preferences. This data stays in your browser and is not sent to us.
Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection. To exercise them: contact@semaphotographie.fr. You may also lodge a complaint with the French supervisory authority, the CNIL (www.cnil.fr).
Minors and image rights
Sessions may involve children. Their photographs are only taken and processed with the consent of a holder of parental authority, who exercises their rights on their behalf.
No client photograph is used for showcase purposes (portfolio, website, social media) without prior written consent.
Security
The site is served over HTTPS. Gallery access codes are stored hashed, photographs are served through time-limited signed links, and access is protected against repeated attempts.