The purpose of this policy is to inform users of the fillerdistribution.com website about the use of cookies and other trackers, as well as the procedures for processing personal data, in accordance with Regulation (EU) 2016/679 of April 27, 2016 (GDPR), the amended French Data Protection Act (Loi Informatique et Libertés n° 78-17 du 6 janvier 1978 modifiée), and the CNIL recommendation on "cookies and other trackers" (délibération n° 2020-091).
1. What is a cookie?
A cookie is a small text file placed on your device (computer, tablet, smartphone) when you visit a website. It allows the site to remember certain information relating to your visit, in order to facilitate your navigation, secure your session, measure the audience, or personalize the content offered to you.
Cookies have a limited lifespan: they can be deleted at the end of the session (session cookies) or kept on your device for a predefined duration (persistent cookies).
2. Categories of cookies used
2.1 Strictly necessary cookies
These cookies are essential for the proper functioning of the site. They do not require your consent (art. 82 al. 2 de la Loi Informatique et Libertés). Without them, certain essential functionalities (shopping cart, identification, security) would be impossible.
- next-auth.session-token / __Secure-next-auth.session-token — NextAuth session JWT (customer account authentication). Duration: 30 days.
- next-intl-locale — Remembers the chosen display language. Duration: 12 months.
- hmd_cart_id — Identifier of the current shopping cart. Duration: 30 days.
- __Host-csrf — Anti-CSRF token for forms. Duration: session.
- cookie_consent — Remembers your choice regarding non-essential cookies. Duration: 6 months.
2.2 Audience measurement cookies (subject to consent)
These cookies allow us to understand how visitors use the site (pages viewed, time spent, journey) in order to improve its ergonomics and content. They are only placed after your explicit consent via the cookie banner.
- _ga, _gid, _gat — Google Analytics 4 (audience measurement). Duration: 13 months max (IP anonymization enabled).
- _clck, _clsk — Microsoft Clarity (anonymized heatmaps). Duration: 12 months.
2.3 Advertising cookies (subject to consent)
These cookies, placed by our advertising partners, allow us to measure the effectiveness of our campaigns and adapt the advertising content you see on other sites. They are only activated after consent.
- _fbp, fr — Meta (Facebook/Instagram) Ads. Duration: 90 days.
- _gcl_au — Google Ads conversion tracking. Duration: 90 days.
- li_sugr, lidc — LinkedIn Insight Tag (B2B). Duration: 60 days.
3. Consent management
During your first visit, a banner allows you to accept, refuse, or configure the placement of non-essential cookies. You can change your choice at any time from the "Manage my cookies" link located in the footer of the site.
Refusing non-essential cookies does not degrade access to the site, but may limit certain analysis or personalization features.
4. Disabling cookies from your browser
You can also configure your browser to block or delete cookies. The procedures vary depending on the browser:
- Chrome: Settings → Privacy and security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy
- Edge: Settings → Privacy, search, and services
For advertising cookies, you can also visit youronlinechoices.com.
5. Personal data
5.1 Data controller
Filler Distribution — 4 boulevard des Sablons, 92200 Neuilly-sur-Seine, France. Data Protection Officer: dpo@fillerdistribution.com.
5.2 Purposes of processing
- Customer account management (legal basis: performance of a contract): creation, identification, order history.
- Order processing and invoicing (legal basis: performance of a contract + legal accounting obligation): preparation, shipping, accounting.
- Verification of professional qualifications for Pro accounts (legal basis: legal obligation — sale of medical devices reserved for authorized practitioners).
- After-sales service and materiovigilance (legal basis: legal obligation — art. R.5212-12 CSP).
- Commercial communication (legal basis: consent): newsletters, targeted offers.
- Audience measurement and site improvement (legal basis: consent).
- Fraud prevention (legal basis: legitimate interest).
5.3 Retention period
- Account data: duration of the commercial relationship + 3 years for prospecting purposes.
- Invoicing data: 10 years (art. L.123-22 du Code de commerce).
- Professional credentials (RPPS/ADELI/Kbis): duration of the relationship + 5 years.
- Materiovigilance data: 15 years (art. R.5212-15 CSP).
- Cookies: see table above (max 13 months for trackers).
5.4 Recipients
The data is intended for the authorized personnel of Filler Distribution and its technical subcontractors (hosting provider, payment provider PayPlug, carriers Chronopost/DPD/UPS, emailing provider). The data is never sold to third parties for commercial purposes without your explicit consent.
5.5 Transfers outside the EU
Certain subcontractors (Google Analytics, Meta Ads, Microsoft Clarity) may process data in the United States. These transfers are governed by the EU-US Data Privacy Framework or by the Standard Contractual Clauses of the European Commission (decision 2021/914).
5.6 Your GDPR rights
In accordance with articles 15 to 22 of the GDPR, you have the following rights:
- Right of access: obtain confirmation that data concerning you is being processed and receive a copy of it.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): subject to legal retention obligations.
- Right to restriction of processing: temporarily restrict processing.
- Right to object: in particular to processing for prospecting purposes.
- Right to data portability: recover your data in a structured and readable format.
- Right to withdraw your consent at any time, without affecting the lawfulness of prior processing.
- Right to define post-mortem directives regarding the fate of your data after your death.
To exercise these rights, write to the DPO at dpo@fillerdistribution.com, attaching a copy of an identity document (which will not be kept beyond the verification process).
You also have the right to lodge a complaint with the CNIL in the event of an observed breach: www.cnil.fr/fr/plaintes.
6. Security
Filler Distribution implements appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction (TLS 1.3 encryption, bcrypt password hashing, restricted access, audit logs, off-site encrypted backups).
7. Contact
For any questions regarding this policy: dpo@fillerdistribution.com or by mail to Filler Distribution, 4 boulevard des Sablons, 92200 Neuilly-sur-Seine, France.