PRIVACY POLICY: N LAB (Nutrimuscle) COMPANY

Last updated: 09/30/2025

We attach particular importance to the protection of your personal data. This policy describes the processing we carry out, your rights, and the measures put in place to guarantee the security and confidentiality of your information.

1. Data Controller

N LAB Company – SAS - President / legal representative: Théo Copolata - Share capital: €13,256.22 - Registered office: 38 rue de Berri, 75008 Paris, France - RCS Paris: 845 402 494 - Intra-community VAT number: FR01845402494 - Contact: privacy@nutrimuscle.com | +33 1 59 58 07 94 - Website: www.nutrimuscle.com

The data controller is Nutrimuscle / CDO for all customer and prospect data.

DPO Contact: magali.dasilva@nlaboratoire.com

2. Collected Data and Purposes

Purpose

Collected Data

Legal Basis

Sub-processors

Retention Period

Processing Location

Customer order management Identity, orders, addresses, emails Contract performance Shopify, PayPlug, PayPal, Shopify Payment 5 years after last order EU / Canada / USA
Newsletters & offers Email, first name, opening behavior Consent (opt-in) Klaviyo, Yotpo, Shopify 3 years or until unsubscription EU / USA
Purchase behavior analysis & BI Orders, browsing, pseudonymized data Legitimate interest Fivetran, Google BigQuery, Tableau, Content Square 3 years France / EU / USA
Customer Support (After-Sales Service) Identity, content, order history Legitimate interest Gorgias, Shopify, iAdvise Chat 3 years EU / USA
Loyalty program Identity, email, order history, loyalty points Contract performance / Legitimate interest Yotpo, Shopify 3 years after last activity EU / USA
Abandoned cart recovery Email, first name, product cart Legitimate interest / Consent Klaviyo, Shopify 13 months EU / USA
Predictive marketing / marketing targeting Orders, browsing, segmentation, email Legitimate interest Fivetran, BigQuery, Klaviyo 3 years EU / USA
Merchandising / email personalization Browsing, order history, preferences Legitimate interest Nosto, Webyn, Kameleoon, Klaviyo 3 years EU / USA
Product recommendations Orders, browsing, preferences Legitimate interest Nosto, Webyn, BigQuery 3 years EU / USA
B2B sales Identity, contact details, orders Contract performance Salesforce / ERP 10 years EU
Customer service info Identity, orders, tickets, emails Legitimate interest Gorgias, Shopify, iAdvise Chat 3 years EU / USA
SEO / SEA / targeted advertising Anonymized identifiers, behavior Legitimate interest Semrush, Google Ads, Meta Ads, TikTok Ads, Snapchat Ads 3 years EU / USA

3. Cookies and tracking

We use cookies and tracking tools for:

  • Analytics and user experience improvement (Google Analytics, Content Square, Tableau)
  • Display and recommendation personalization (Nosto, Webyn, Kameleoon)
  • Marketing and targeted advertising (Klaviyo, Google Ads, Meta Ads, TikTok Ads, Snapchat Ads)

Retention period: 13 months for marketing and personalization cookies. You can manage your preferences via the site's cookie banner.

  • Management via GDPR/EU compliant banner
  • Categories: necessary, performance, marketing, social networks
  • Consent required for marketing and tracking cookies
  • Consent modification or withdrawal possible at any time
  • More information on Cookie Policy

4. Transfers outside the EU

Certain data is processed by providers located outside the EU (USA, Canada, Israel). These transfers are governed by Standard Contractual Clauses (SCCs) or DPAs to guarantee a level of protection equivalent to that of the EU.

5. Data security

We implement the following measures:

  • Data encryption in transit and at rest (HTTPS, SSL, AES)
  • Access control and strong authentication (2FA, IAM management)
  • Audit logs and network monitoring
  • Pseudonymization for analytical data

6. Your rights

In accordance with the GDPR, you can:

  • Access your personal data
  • Request its rectification or deletion
  • Obtain the portability of your data
  • Object to certain processing or withdraw your consent
  • File a complaint with the CNIL

To exercise your rights: magali.dasilva@nlaboratoire.com

7. Policy modifications

This policy may be updated regularly. The latest version will always be available on the site.

8. Contact

For any questions regarding personal data or the exercise of rights: - Email: privacy@nutrimuscle.com - Tel: +33 1 59 58 07 94 - Address: 38 rue de Berri, 75008 Paris, France