Welcome to our website’s privacy policy page.
Here you will find out how Novo Déco collects, uses and protects your personal data, in compliance with the GDPR.

Last updated: 30 August 2026

The data controller for personal data collected via https://novo-deco.com is:

  • Company name: Novo-Deco
  • Legal form: Sole proprietorship (Entrepreneur individuel – France)
  • GDPR contact email: contact@novo-deco.fr

We collect the following categories of data:

  • Identification and contact data: name, first name, email address.
  • Message / project data: name, first name, email address, message content.
  • Technical data: connection logs, security logs (for example in the event of an attempted intrusion).

We do not collect payment data, health data, or sensitive data, unless you explicitly provide them (for example in a message). In that case, please avoid sending unnecessary sensitive data.

The website does not use cookies.
No data is stored via cookies on your device.

Each processing activity has a specific legal basis:

  • Managing contact and project requests: responding to your inquiries, discussing your projects, offering interior architecture services.
    • Legal basis: performance of pre-contractual measures (Article 6.1.b GDPR).
  • Legal obligations: retention of certain data (e.g. invoices if a service is provided, correspondence in case of dispute).
    • Legal basis: legal obligation (Article 6.1.c GDPR).
  • Legitimate interest: site security, fraud prevention, improving user experience (security logs, internal anonymous statistics).
    • Legal basis: legitimate interest (Article 6.1.f GDPR), balanced against your rights.

No processing is based on consent for cookies, as no cookies are used.

Your data may be shared with the following categories of recipients:

  • Internally: the interior architect and, if applicable, persons responsible for site management and client relations.
  • Processors (service providers):
    • Website host: IONOS (European Union).
    • WordPress extensions (e.g. WPForms, Yoast, Polylang, etc.): some technical data may pass through their servers according to their own privacy policy.
    • Anti-spam / security services.

These providers act on our instructions, under contracts compliant with the GDPR (standard contractual clauses if outside the EU).

Some providers (for example plugin vendors or security services) may be located outside the European Union. In such cases, we ensure that appropriate safeguards are in place (European Commission adequacy decisions, standard contractual clauses, or other GDPR-compliant mechanisms).

We retain data according to the purpose:

  • Contact / project request data: 3 years after the last contact, unless you become a client (in which case, retention according to legal obligations, notably 10 years for invoices).
  • Security logs: typically between 6 months and 2 years depending on log type and purpose.

No retention period related to cookies applies, as the site does not use cookies.

We implement technical and organizational measures to protect your data:

  • Encryption of communications (HTTPS/TLS).
  • Restricted access to personal data (authentication, roles, access logs).
  • Regular updates of WordPress, themes, and plugins.
  • Regular backups and restoration tests.
  • Monitoring and management of security incidents.

In the event of an incident likely to result in a high risk to your rights, we will notify you in accordance with the GDPR.

Some pages may include embedded content (YouTube videos, Google Maps, Instagram posts, etc.).

This content behaves as if you were visiting the third-party site directly. These sites may:

  • Collect data about you,
  • Use cookies,
  • Embed third-party tracking tools,
  • Track your interactions with this content, especially if you are logged into your account on these sites.

We invite you to consult the privacy policies of these third-party services..

Under the GDPR and the French Data Protection Act (loi Informatique et Libertés), you have the following rights:

  • Right of access: to know what data we hold about you.
  • Right to rectification: to correct inaccurate or incomplete data.
  • Right to erasure: to request deletion of your data, subject to legal obligations (e.g. invoices, security).
  • Right to restriction of processing: to limit the use of certain data.
  • Right to data portability: to receive your data in a structured, commonly used format.
  • Right to object: to object, on legitimate grounds, to certain processing (e.g. direct marketing).
  • Right to withdraw consent: at any time (e.g. newsletter).

To exercise these rights, contact us at: contact@novo-deco.fr, providing proof of identity and, if necessary, a copy of an ID document.
We respond within one month, extendable to two months for complex requests.

You also have the right to lodge a complaint with the CNIL (https://www.cnil.fr) if you believe your rights are not respected.

We may update this policy to reflect changes in our practices or the law.
The current version is the one published on the site, with the last updated date shown at the top of the page.

For any questions regarding this policy or data protection:

  • Email : contact@novo-deco.fr