PRIVACY POLICY

1. INTRODUCTION

ESPACE ECOMMERCE FRANCE

(hereinafter the “Controller” or “we”) attaches great importance to the protection of the privacy and personal data of the users of the website www.justbob.shop (hereinafter the “Site”).

This Privacy Policy (hereinafter the “Privacy Policy”) describes the purposes, methods, legal bases and retention periods of the personal data collected through the Site. It has been drawn up in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the “GDPR”), with Directive 2002/58/EC (ePrivacy Directive) as amended by Directive 2009/136/EC, and with the corresponding national transpositions in each Member State of the European Union and the European Economic Area where the Site is accessed by users. Reference is also made to the guidelines of the European Data Protection Board (EDPB) and to the positions of the Commission nationale de l’informatique et des libertés (CNIL) as the lead supervisory authority of the Controller.

This Privacy Policy concerns exclusively the processing of personal data carried out through the Site and does not extend to third-party websites accessible by users through links present on the Site. The Controller is not responsible for the processing of personal data by third-party sites accessed by the user at his own responsibility. For all information on cookies and other tracking technologies used on the Site, please refer to our Cookie Policy, which complements this Privacy Policy.

In accordance with Article 5 of the GDPR, the processing of personal data is carried out in compliance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality. The Controller is in a position to demonstrate the conformity of its processing activities with the principles of the Regulation, in accordance with Article 5(2) of the GDPR (accountability principle).

The user is invited to read this Privacy Policy carefully before providing any personal data to the Site. The use of the Site, the creation of a customer account, the placing of an order or the sending of a message through the contact form imply that the user has acknowledged this Privacy Policy.

2. DATA CONTROLLER

The Controller of the personal data collected through the Site is:

ESPACE ECOMMERCE FRANCE SARL

  • Legal form: Société à Responsabilité Limitée (SARL) under French law
  • Registered office: 16 rue Cuvier, 69006 Lyon (France)
  • EU VAT number: FR62920502598
  • SIREN: 920 502 598
  • SIRET: 920 502 598 00013
  • NAF/APE code: 47.91A
  • Share capital: 2,000.00 EUR
  • Email: info@justbob.shop
  • Telephone: +44 2030514261 (Monday to Friday, 10:00 to 17:00 CET, excluding public holidays)
  • Website: www.justbob.shop

Considering the nature and scope of the processed data, as well as the absence of regular and systematic monitoring of data subjects on a large scale or of large-scale processing of special categories of data, the Controller is not required to designate a Data Protection Officer within the meaning of Article 37 of the GDPR. Any request relating to the processing of personal data, including the exercise of the rights recognised in Articles 15 to 22 of the GDPR, may be addressed to the email address info@justbob.shop, which serves as the preferred channel of communication with the Controller in data protection matters.

The Controller has its sole establishment in France: the Commission nationale de l’informatique et des libertés (CNIL) is therefore the lead supervisory authority within the meaning of Article 56 of the GDPR. The user may also lodge a complaint with the supervisory authority of his country of habitual residence within the European Union, in accordance with the one-stop-shop mechanism set out in Article 60 of the GDPR (see Section 12.3 of this Privacy Policy).

3. PERSONAL DATA COLLECTED

Depending on the user’s interaction with the Site, the Controller may collect the following categories of personal data:

  1. a) Identification and contact data: name, surname, postal address, email address, telephone number.
  2. b) Billing data: billing address (if different from the delivery address), tax identification number or VAT identification number (in cases where the customer requests an invoice).
  3. c) Transaction data: purchased products, amount, payment method (masked payment data), order number, order history.
  4. d) Customer account data: username, password (stored in encrypted form using a secure hash algorithm), account settings.
  5. e) Navigation data: IP address (anonymised for analytical purposes), browser type and version, operating system, pages visited, date and time of each access, referring URL. This data is automatically collected by the Site’s IT systems (see Section 4).
  6. f) Communication data: content of messages sent by email or through the contact form, history of communications with customer service, any attachments or order references useful to handle the request.

The Controller collects exclusively personal data that is strictly necessary for the proper operation of the Site, the provision of the requested services and the fulfilment of legal obligations, in full compliance with the principle of data minimisation set out in Article 5(1)(c) of the GDPR. The collection of additional data beyond those mentioned, where required for special purposes, will be subject to prior information and, where required by law, to express consent.

The Controller does not collect or process special categories of personal data within the meaning of Article 9 of the GDPR, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, data concerning a natural person’s sex life or sexual orientation. The Products sold on www.justbob.shop are intended exclusively for technical, scientific, ornamental, collectible or room-fragrance purposes and are not offered as medicinal products, food supplements, food or cosmetics. The purchase of such Products does not allow any inference about the health status of the data subject. In the event of a spontaneous transmission of special categories data by the user, the Controller will refrain from processing them and will proceed with their secure deletion in the shortest possible time.

4. NAVIGATION DATA

The IT systems and software procedures used to operate the Site automatically collect, in the course of their normal operation, certain personal data whose transmission is implicit in the use of internet communication protocols. This data includes:

  • IP addresses (anonymised for analytical purposes)
  • browser type and version
  • operating system
  • pages visited and navigation path
  • date and time of each server request
  • referring URL (the page from which the user accessed the Site)
  • internet service provider (ISP)

This data is used exclusively for the purpose of ensuring the proper functioning of the Site and the security of the system, for example to detect unauthorised access, intrusion attempts, computer attacks of the Brute-Force or DDoS type or other threats to the availability and integrity of the service. The processing serves the ordinary maintenance of the infrastructure and the aggregated statistical analysis of traffic to optimise the technical operation of the Site.

The legal basis of the processing is the legitimate interest of the Controller (Article 6(1)(f) of the GDPR) in ensuring network and information security, in accordance with Recital 49 of the GDPR. This legitimate interest has been subjected to a specific balancing assessment with the rights and freedoms of the data subjects (Legitimate Interest Assessment), which has confirmed the proportionality of the processing in relation to the pursued purpose.

Navigation data is stored in the server log files for a maximum period of 12 months and then automatically deleted, subject to the necessity of longer retention in the context of investigations by competent authorities in cases of security incidents or judicial proceedings.

5. DATA VOLUNTARILY PROVIDED BY THE USER

The user may voluntarily provide personal data in the following cases:

  1. a) Customer account registration: when creating a customer account on the Site, name, surname, email address and password are required. This data is necessary for the creation and management of the customer account (legal basis: Article 6(1)(b) GDPR, performance of the contract). Refusal to provide it prevents registration and access to the functions reserved for registered users.
  2. b) Placing of orders: to execute an order, name, surname, delivery address, email address and telephone number are required. This data is essential for the performance of the sales contract (legal basis: Article 6(1)(b) GDPR). Payments are processed by external authorised payment service providers in an environment compliant with PCI DSS standards: the Controller does not store complete payment card data and does not have access to it.
  3. c) Contact form and email: the voluntary sending of emails or the completion of the contact form entails the collection of the sender’s email address and any other personal data contained in the message, exclusively for the purpose of handling the request (legal basis: Article 6(1)(b) GDPR).
  4. d) Newsletter subscription: the user may voluntarily subscribe to the newsletter by providing his email address. Most restrictive cross-jurisdiction approach:

The sending of commercial communications (newsletter, promotional offers, information on new products) by electronic means is carried out exclusively on the basis of the user’s prior, express and freely given consent, in accordance with Article 6(1)(a) GDPR and Article 13 of Directive 2002/58/EC (ePrivacy).

In view of the heterogeneity of the national transpositions of the ePrivacy Directive (some Member States, such as Germany, Austria, Italy and France, allow the so-called “soft opt-in” for existing customers in relation to similar goods or services; other Member States, such as Poland, do not provide such an exemption), the Controller has adopted the most restrictive cross-jurisdictional approach and requires explicit consent in all cases. Even if the user has concluded a sales contract with the Controller, the Controller will not send marketing communications without the user’s prior, express consent.

The consent is freely given and is not a condition for the conclusion or performance of the sales contract. It can be withdrawn at any time, free of charge and without any specific formality, by clicking the unsubscribe link in any received marketing communication or by sending an email to info@justbob.shop. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal (Article 7(3) GDPR).

The sending of emails is handled by Brevo SAS (formerly Sendinblue), which acts as a data processor within the meaning of Article 28 of the GDPR.

  1. e) Fraud prevention and legal defence: all collected personal data may, where necessary, be processed for the purpose of preventing fraud, protecting against conducts contrary to the Terms and Conditions of the Site and defending the rights of the Controller in court or out of court (legal basis: Article 6(1)(f) GDPR, legitimate interest). In such cases, the data subject retains the right to object pursuant to Article 21 of the GDPR.

6. PURPOSES AND LEGAL BASES OF PROCESSING

The personal data collected through the Site is processed for the following purposes, each with its own legal basis:

PurposeLegal basis (Art. 6 GDPR)Processed data
Order processing and execution (including shipping and delivery)Art. 6(1)(b) GDPR, performance of the contractName, surname, delivery address, email, telephone, order data
Customer account creation and managementArt. 6(1)(b) GDPR, performance of the contractName, email, password (hash), settings
Compliance with tax and accounting obligationsArt. 6(1)(c) GDPR, legal obligation (Article L.123-22 French Code de commerce)Name, billing address, transaction data, tax/VAT number
Customer service and after-sales supportArt. 6(1)(b) GDPR, performance of the contractName, email, communication history
Sending of marketing communications (newsletter)Art. 6(1)(a) GDPR, consent (explicit opt-in always required)Email address
Technical monitoring of Site performance (Google Analytics 4, anonymised)Art. 6(1)(f) GDPR, legitimate interest in maintenance and technical improvement of the serviceAnonymised navigation data (truncated IP address), no personal identification data
Site security and fraud preventionArt. 6(1)(f) GDPR, legitimate interestIP address, access logs, device data
Defence of rights in judicial or out-of-court proceedingsArt. 6(1)(f) GDPR, legitimate interestAll data strictly necessary for the defence

Note on legitimate interest: where the legal basis of the processing is the legitimate interest of the Controller, the data subject has the right to object at any time to the processing on grounds relating to his particular situation, in accordance with Article 21 of the GDPR. In such case, the Controller will refrain from processing the data unless it can demonstrate compelling legitimate grounds for the processing that override the interests, rights and freedoms of the data subject, or unless the processing is necessary for the establishment, exercise or defence of legal claims. To exercise the right to object, the data subject may send an email to info@justbob.shop.

Note on consent: the consent given for the sending of marketing communications and for any other processing based on Article 6(1)(a) GDPR may be withdrawn at any time with the same ease with which it was given, without prejudice to the lawfulness of the processing carried out before the withdrawal (Article 7(3) GDPR). The withdrawal of consent has no retroactive effect on processing already carried out.

Provision of data and consequences of refusal: the provision of data necessary for the performance of the contract (orders, customer account) and for the fulfilment of legal obligations (invoicing, tax retention) is mandatory: failure to provide it prevents the Controller from fulfilling the data subject’s request. The provision of data for marketing purposes (newsletter) is, on the other hand, voluntary and does not affect in any way the possibility of using the Site and the services.

7. DATA PROCESSORS (ART. 28 GDPR)

To provide our services, personal data may be processed by the following data processors, with whom the Controller has concluded the corresponding data processing agreements (DPA) within the meaning of Article 28 of the GDPR:

Data ProcessorServiceRegistered office
Planetel S.p.A. (formerly NetAdmin S.r.l.)Site hosting and server maintenanceVia Mattei 10, 24060 Brusaporto (BG), Italy (EU)
Brevo SAS (formerly Sendinblue)Sending of transactional communications relating to orders and the newsletter7 rue de Madrid, 75008 Paris, France (EU), RCS Paris 498 019 298
Google LLCAnonymised technical monitoring of Site performance (Google Analytics 4)1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (certified under EU-US Data Privacy Framework)

Payment processing is carried out by external authorised payment service providers, who, depending on the specific phase of the processing, act as separate controllers or as data processors, applying their own privacy policies and security measures compliant with the PCI DSS standard. The Controller does not store complete payment data (card numbers, CVV, security codes) and does not have direct access to it: it receives only the information about the outcome of the transaction necessary to process the order.

The data processors are selected by the Controller from providers that offer sufficient guarantees that appropriate technical and organisational measures will be implemented in such a way that the processing complies with the requirements of the GDPR and ensures the protection of the rights of the data subject (Article 28(1) of the GDPR). Each data processor is bound by a written contract (Data Processing Agreement) which specifically governs the nature, duration, purposes and categories of the processed data, the obligations of confidentiality, the security measures, the management of further sub-processors, the cooperation in the exercise of the rights of the data subject and in the notification of any breaches.

The complete and updated list of data processors, including any further sub-processors appointed by the main data processors, is available on request at info@justbob.shop.

8. DISCLOSURE TO THIRD PARTIES

The Controller does not sell, rent or transfer personal data to third parties.

Personal data may be disclosed exclusively for the purposes indicated in this Privacy Policy to the following categories of recipients:

  1. a) Data Processors (Article 28 GDPR): third-party providers that process personal data on behalf of the Controller on the basis of a data processing agreement. See Section 7 for details.
  2. b) Professionals and consultants: firms and professionals providing the Controller with accounting, administrative, legal, tax, financial or debt collection services, acting depending on the case as data processors or as separate controllers.
  3. c) Public authorities: authorities, offices or bodies to which the disclosure of personal data is mandatory pursuant to legal provisions or reasoned requests of the competent authorities (for example judicial authorities, law enforcement authorities, tax authorities).
  4. d) Authorised personnel: collaborators and employees of the Controller who are expressly authorised to process personal data in accordance with Article 29 of the GDPR and are subject to specific instructions and confidentiality obligations.

Personal data is in no case publicly disclosed.

9. INTERNATIONAL DATA TRANSFERS

Some data processors may process personal data outside the European Economic Area (EEA). In particular:

Data ProcessorCountryApplied safeguard
Google LLC (Google Analytics 4)United StatesCertified under the EU-US Data Privacy Framework (DPF), subject to Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequacy of the level of protection of personal data. The DPF certification of Google LLC can be consulted in the public register at www.dataprivacyframework.gov. In addition to the DPF, the Controller has activated the anonymisation of the IP address (IP-Masking) to minimise the personal data transmitted.
Brevo SASFrance (EU)Servers within the European Union. No transfer outside the EEA.
Planetel S.p.A.Italy (EU)Servers within the European Union. No transfer outside the EEA.

In the event of an invalidity declaration or amendment of the EU-US Data Privacy Framework, the Controller will adopt the necessary safeguards, in particular the standard contractual clauses approved by the European Commission with Implementing Decision (EU) 2021/914 of 4 June 2021, where appropriate supplemented by additional technical (encryption, pseudonymisation, anonymisation of identifiers) and contractual measures, in order to ensure an adequate level of protection of personal data.

The validity of the EU-US Data Privacy Framework was confirmed by the General Court of the European Union with its judgment T-553/23 Latombe of 3 September 2025. An appeal before the Court of Justice has been lodged on 31 October 2025 and is currently pending. The Controller continuously monitors the development of the legal framework on international data transfers, including case-law developments on the validity of the DPF, and undertakes to update this Privacy Policy and, where appropriate, the legal bases of the transfers.

For further information on the safeguards applied to international data transfers, including a copy or reference to any standard contractual clauses used, the data subject may send an email to info@justbob.shop.

10. PROCESSING METHODS AND SECURITY

Personal data is processed using IT and telematic tools, according to logics strictly related to the purposes indicated in this Privacy Policy and in any case in such a way as to ensure its security and integrity.

In accordance with Article 32 of the GDPR, the Controller takes appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • encryption of communications using the HTTPS protocol (TLS 1.2 / 1.3) on the entire Site
  • storage of passwords using secure hash algorithms (bcrypt / scrypt)
  • restriction of access to personal data to expressly authorised personnel with individual access credentials
  • daily and weekly backups of systems and databases, stored in encrypted form
  • monitoring of access logs to detect unauthorised access attempts
  • regular updates of the CMS, plug-ins and software used
  • hosting infrastructure compliant with the security standards declared by the provider

Automated decision-making and profiling: the Controller does not take decisions based solely on automated processing and does not perform profiling that produces legal effects vis-à-vis the data subject or similarly significantly affects the data subject, within the meaning of Article 22 of the GDPR.

Personal data breach (Data Breach): the Controller has implemented an internal procedure for the management of personal data breaches, which governs the methods of detection, analysis, risk classification, notification and communication and the maintenance of the internal register of breaches. In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, the Controller will notify the competent supervisory authority within 72 hours of becoming aware of it, in accordance with Article 33 of the GDPR and, where the breach is likely to result in a high risk to the rights and freedoms of natural persons, will promptly communicate the event to the data subjects in accordance with Article 34 of the GDPR.

Where the breach involves a high risk for the rights and freedoms of the data subjects, the communication to the data subjects is made by email at the address communicated to the Controller by the user, with a description in plain and clear language of the nature of the breach, the likely consequences, the measures taken or proposed to remedy and contain it and the contact details to obtain further information.

11. RETENTION PERIOD

Personal data is retained for the period strictly necessary to achieve the purposes for which it was collected, and in any case in compliance with the following periods:

PurposeRetention periodLegal basis
Order processing and tax/accounting documentation10 years from the end of the financial year of the last entryArticle L.123-22 French Code de commerce (most conservative cross-jurisdictional standard)
Customer account dataUntil deletion of the customer account by the user, plus the statutory limitation period applicable to potential claims under the law of the user’s habitual residence (typically 3 to 6 years)Art. 6(1)(b) GDPR; applicable national civil law on limitation periods
Customer service3 years from the last communicationArt. 6(1)(b) GDPR; principle of proportionality having regard to applicable national limitation periods
Marketing communications (newsletter)Until withdrawal of consent or objection of the data subjectArt. 6(1)(a) GDPR; Art. 21(3) GDPR
Technical monitoring of the Site (Google Analytics 4, anonymised)Maximum 14 months (GA4 configuration)Art. 6(1)(f) GDPR, legitimate interest
Navigation data (server logs)12 monthsArt. 6(1)(f) GDPR, legitimate interest in system security
Data relating to the exercise of data subject rights3 years from the last requestArt. 6(1)(c) GDPR; accountability principle (Art. 5(2) GDPR)

After the indicated periods, personal data is securely deleted or irreversibly anonymised, subject to legal obligations requiring longer retention (for example tax obligations, anti-money laundering, judicial protection).

Note on the most conservative tax retention standard: ESPACE ECOMMERCE FRANCE SARL is a French company. French law sets the retention obligation for accounting documents at ten years from the close of the financial year (Article L.123-22 of the French Code de commerce). The Controller applies this period as the most conservative standard, even where the user is established in a Member State with a shorter local retention period (for example 5 years in Poland, 7 years in Austria, 10 years in Germany and Italy). This approach ensures cross-jurisdictional compliance without prejudicing user rights.

Criteria for determining the retention period: for purposes for which a precise period is not indicated, the Controller determines the retention period of the data on the basis of the following criteria: (i) duration of the contractual or pre-contractual relationship with the data subject; (ii) any legal, regulatory or contractual retention obligations; (iii) limitation periods applicable to claims that can be brought against the Controller, in accordance with the civil law of the user’s country of habitual residence; (iv) recommendations of the EDPB and CNIL on data minimisation in storage.

12. DATA SUBJECT RIGHTS

In accordance with Articles 15 to 22 of the GDPR, the data subject has the following rights vis-à-vis the Controller:

RightDescriptionLegal basis
AccessTo obtain confirmation as to whether or not personal data is being processed and, if so, access to such data and to the information on the processingArt. 15 GDPR
RectificationTo obtain rectification of inaccurate data or completion of incomplete dataArt. 16 GDPR
Erasure (Right to be Forgotten)To obtain erasure of personal data when it is no longer necessary for the purposes for which it was collected, in case of withdrawal of consent, objection, unlawful processing or to comply with a legal obligationArt. 17 GDPR
Restriction of processingTo request a temporary suspension of the processing in certain cases (contesting accuracy, unlawful processing, need of data for legal defence, pending objection)Art. 18 GDPR
Data portabilityTo receive personal data in a structured, commonly used and machine-readable format and to transmit it to another controller, where the processing is based on consent or on the performance of a contract and is carried out by automated meansArt. 20 GDPR
ObjectionTo object to the processing of personal data on grounds relating to the particular situation, in particular where the legal basis is legitimate interest. For direct marketing, the right to object is unconditional and unlimitedArt. 21 GDPR
Withdrawal of consentTo withdraw the consent given at any time with the same ease with which it was given, without prejudice to the lawfulness of the processing carried out before the withdrawalArt. 7(3) GDPR
No automated individual decision-makingNot to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects the data subjectArt. 22 GDPR

12.1 Modalities of exercise of rights

The data subject may exercise one or more of these rights by sending a request to the Controller through the following channels:

  • Email: info@justbob.shop
  • Postal address: ESPACE ECOMMERCE FRANCE SARL, 16 rue Cuvier, 69006 Lyon, France

The request must contain the name, the email address associated with the customer account (if any) and a clear description of the right exercised. The Controller may request documents to verify the identity of the data subject, with the sole purpose of preventing unauthorised access to data of third parties, in accordance with Article 12(6) of the GDPR. In line with the recommendations of the supervisory authorities, the request for identity documents is limited to cases of objective doubt, and the documents transmitted are destroyed as soon as the identity is verified, subject to contrary legal provisions.

If the Controller is unable to identify the data subject on the basis of the information received, he will inform the data subject without delay and may, in accordance with Article 11(2) of the GDPR, refuse to comply with the request, subject to the possibility for the data subject to provide additional information for identification.

12.2 Response times

The Controller responds to requests within a period of one (1) month from receipt. This period may be extended by a further two (2) months taking into account the complexity and the number of requests (a maximum of three months in total), with reasoned communication to the data subject within the first month (Article 12(3) GDPR).

The response to the request is free of charge, except in cases of manifestly unfounded or excessive requests, in particular where they are repetitive, for which the Controller may charge a reasonable fee to cover the costs incurred or refuse to comply with the request (Article 12(5) GDPR).

12.3 Right to lodge a complaint with a supervisory authority

If the data subject considers that the processing of his personal data does not comply with the applicable provisions, he has the right, in accordance with Article 77 of the GDPR, to lodge a complaint with a supervisory authority.

Since the Controller has its sole establishment in France, ESPACE ECOMMERCE FRANCE SARL is subject to the European one-stop-shop mechanism set out in Articles 56 and 60 of the GDPR.

Lead Supervisory Authority pursuant to Article 56 GDPR:

CNIL Commission nationale de l’informatique et des libertés

  • Registered office: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
  • Telephone: +33 (0)1 53 73 22 22
  • Website: www.cnil.fr
  • Online complaint: www.cnil.fr/fr/plaintes
  • Postal address for complaints: CNIL, Service des Plaintes, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France

National supervisory authority of the user’s habitual residence:

The user retains the right, pursuant to Article 77 of the GDPR, to lodge a complaint with the supervisory authority of the country of his habitual residence, of his place of work or of the place of the alleged infringement. The complete and updated list of national supervisory authorities of the European Union is available on the website of the European Data Protection Board:

In addition to the administrative remedy, the data subject is entitled to an effective judicial remedy in accordance with Article 78 of the GDPR vis-à-vis the supervisory authority and Article 79 of the GDPR vis-à-vis the Controller, before the competent courts, in particular before the courts of his habitual residence, in accordance with Regulation (EU) 1215/2012 (Brussels I bis), Articles 17 to 19. The judicial remedy may be brought alternatively or cumulatively to the administrative complaint and aims at the effective protection of the rights recognised by the GDPR, including the right to compensation under Article 82 of the Regulation.

13. MINORS

The website www.justbob.shop is reserved exclusively to adult persons (18 years of age or older). The Controller does not knowingly collect or process personal data from minors under 18 years of age. Should the Controller become aware that personal data of a minor under 18 years of age has been processed, such data will be deleted promptly, subject to legal retention obligations.

In accordance with Article 8 of the GDPR, the minimum age for valid consent to the processing of personal data in the context of the direct offering of information society services is 16 years as a default rule at Union level. Member States may provide for a lower age, by national law, provided that such lower age is not below 13 years. Several Member States have made use of this possibility (for example Austria has set the age at 14, France at 15, Italy and Belgium at 14, Sweden at 13). For the purposes of this Privacy Policy, the default GDPR age of 16 applies, unless the user’s national law provides for a lower threshold and the user is in the corresponding age range. In any event, the access to the website is reserved to persons aged 18 and over, so the digital consent age threshold has no practical effect.

If a parent or legal guardian believes that a minor under 18 years of age has provided personal data to the Controller, they may send an email to info@justbob.shop requesting deletion. The Controller will comply with the request without undue delay, taking all reasonable steps to verify the requester’s status as a holder of parental authority or guardianship, with respect for the rights of any other data subjects.

The Controller also takes technical and organisational measures to make access to the Site by minors more difficult, including the presence of indications on the required minimum age, declarations of age conditions during the registration and payment phases and monitoring of any access patterns attributable to minors.

14. AMENDMENTS TO THIS PRIVACY POLICY

The Controller reserves the right to modify or update this Privacy Policy at any time, in order to adapt it to new legal requirements, developments in case-law, decisions of the supervisory authorities or industry best practices.

Any material amendment will be communicated to users through a notice published on the Site with reasonable notice prior to the entry into force of the new provisions and, in the cases provided for by law, by direct communication by email to the registered users.

It is recommended to consult this Privacy Policy regularly. The “Last updated” date at the beginning of the document allows the user to verify the time of the last amendment.

If the amendments entail a change in the purposes or legal bases of the processing, the Controller will obtain the new consent of the data subject where required by the applicable provisions. Until the actual granting of new consent, the Controller will continue to process the data on the basis of the previously given consent, within the scope of the originally indicated purposes.

15. APPLICABLE LAW AND JURISDICTION

This Privacy Policy is governed by French law, as the law of the country of establishment of the Controller, in particular the GDPR, the French Data Protection Act (Loi n° 78-17 of 6 January 1978 on data processing, files and freedoms, as amended) and other applicable national provisions. In any event, the mandatory consumer protection provisions of the country of habitual residence of the user within the European Union or the European Economic Area remain unaffected, in accordance with Article 6 of Regulation (EC) 593/2008 (“Rome I”).

For any dispute arising from the interpretation or application of this Privacy Policy, the courts of the place of habitual residence of the consumer are competent, in accordance with Regulation (EU) 1215/2012 (“Brussels I bis”), Articles 17 to 19, and the procedural rules of the country of habitual residence. The right of the data subject to bring a judicial remedy under Articles 78 and 79 of the GDPR is in any event preserved.

The user, in his capacity as consumer, may also resort to the alternative dispute resolution (ADR) mechanisms provided for by national and Union law. To this end, the European Commission makes available an official portal for the consultation of alternative dispute resolution (ADR) bodies operating in each Member State of the European Union, accessible at https://consumer-redress.ec.europa.eu/, in accordance with Regulation (EU) 2024/3228, which repealed Regulation (EU) No. 524/2013 with effect from 20 July 2025. The use of these mechanisms is voluntary and does not deprive the consumer of the right to bring proceedings before the competent court.

16. CONTACT

For any question, request or communication relating to this Privacy Policy or to the processing of personal data, the data subject may contact the Controller through the following channels:

ESPACE ECOMMERCE FRANCE SARL

  • Postal address: 16 rue Cuvier, 69006 Lyon, France
  • Email: info@justbob.shop
  • Telephone: +44 2030514261
  • Customer service hours: Monday to Friday, 10:00 to 17:00 CET, excluding public holidays
  • Website: www.justbob.shop

The preferred channel for the exercise of data subject rights and for any communication relating to the processing of personal data is the email address info@justbob.shop.

Requests from data subjects are processed in chronological order of receipt. For complex or particularly important requests, the Controller reserves the possibility of contacting the data subject to ask for clarifications, with the sole purpose of providing a more targeted and accurate response.

For greater clarity and transparency, it is recalled that this Privacy Policy is complemented by the Cookie Policy and by the Terms and Conditions of the Site, available in the corresponding sections of www.justbob.shop. The joint reading of these documents allows the user to obtain a complete overview of his rights and obligations as a data subject and as a consumer.

Last updated: 30 April 2026