PRIVACY POLICY

SanaSarah LLC - Trade name : Esentiara
Last updated : September 2025

Entity : SanaSarah LLC
Address : 30 N Gould St, Ste R, Sheridan, WY 82801, USA
Data Protection Contact : dpo@esentiara.com
Website : https://www.esentiara.com

2.1 Identification Information
When creating an account:
– Last name, first name
– Email address
– Password (encrypted)
– Date of birth (optional)
– Phone number (optional)

When placing an order:
– Full billing address
– Shipping Address
– Payment information (via secure service providers)

2.2 Navigation Data
Collected automatically:
– IP address
– Browser type and version
– Operating System
– Pages visited and duration
– Reference (original site)
– Date and time of login

2.3 Transaction Data
Purchase History:
– Ordered Products
– Amounts and currencies
– Order Dates
– Delivery Status
– Returns and Exchanges

2.4 Communication Data
Correspondence :
– Emails exchanged with customer service
– Messages sent via contact forms
– Product Reviews and Comments
– Requests for cancellation or complaints

2.5 Sensitive Data (Pensions and Well-Being Only)
Data collection with explicit consent:
– Food or medication allergies
– Specific medical conditions
– Physical limitations or disabilities
– Dietary preferences (vegetarian, etc.)

 

3.1 Performance of the Contract
– Order Processing and Tracking
– Billing and Accounting
– Product Delivery
– Customer Service
– Returns and Refunds Management

3.2 Legal Obligations
– Retention of invoices (10 years)
– Tax Returns
– Combating Fraud
– Compliance with trade embargoes

3.3 Legitimate Interests
– Transaction Security
– Fraud Prevention
– Improving our services
– Anonymized statistical analyses

3.4 Consent (revocable)
– Sending newsletters
– Personalized marketing
– Non-essential cookies
– Customer Reviews

[wpdatatable id=1]

5.1 Active Customer Data
During the business relationship and for 3 years after the last order

5.2 Prospect Data
3 years after the last contact or withdrawal of consent

5.3 Accounting Data
10 years (legal tax requirement)

5.4 Marketing Data
3 years after withdrawal of consent or inactivity

5.5 Technical Data
Up to 13 months (cookies, connection logs)

5.6 Sensitive Data
Immediate deletion upon completion of the retirement period (unless required by law)

6.1 Authorized Personnel
Strictly necessary access:
– Customer Service Team
– Logistics Manager
– Accounting
– Management (supervision)

6.2 GDPR Data Processors
With contractual guarantees:

Accommodations:
– Servers located in the European Union
– ISO 27001 Certification
– Standard Contractual Clauses

Payment:
– Stripe Inc. (United States) – PCI DSS Certification
– PayPal Inc. (United States) – Data Privacy Framework
– We do not store any banking information

Transportation:
– Authorized European carriers
– Transmission of delivery data only
– Deletion after delivery

Communication:
– GDPR-certified email marketing provider
– EU servers only
– Encryption of transmissions

6.3 Authorities
Only upon a court order or legal obligation

6.4 No Sale of Data
Firm Commitment : We do not sell your personal data

7.1 Principle
EU Priority : Primary treatment in the European Union

7.2 Transfers to the United States
Appropriate guarantees:
– European Commission Model Contract Clauses 2021/914
– Certified payment processors (Stripe, PayPal)
– Transfer Impact Assessment (TIA)
– AES-256 encryption required

7.3 Other Countries
Prohibited except:
– European Commission Adequacy Decision
– Appropriate guarantees (SCC, BCR, certifications)
– Exceptions under Article 49 of the GDPR (performance of a contract, consent)

8.1 Right of Access (Art. 15)
Get :
– Confirmation of processing
– Copy of your data
– Information on treatments

8.2 Right to Rectification (Art. 16)
Correct :
– Inaccurate data
– Incomplete data
– Update profile

8.3 Right to Erasure (Art. 17)
Delete if:
– Unnecessary data
– Withdrawal of consent
– Illegal processing
– Legal requirement

Exceptions :
– Accounting bonds (10 years)
– Defending our rights in court
– Public interest

8.4 Right to Restriction (Art. 18)
Temporary suspension of treatment in the event of:
– Dispute regarding accuracy
– Illegal processing
– Objection to treatment

8.5 Right to Data Portability (Art. 20)
Recovering Your Data:
– Structured format (JSON, CSV)
– Direct transmission possible
– Data provided with consent

8.6 Right to Object (Art. 21)
Rejected for:
– Processing for marketing purposes
– Advertising profiling
– Legitimate interest (legitimate grounds required)

8.7 Rights Regarding Automated Decisions (Art. 22)
Protection against:
– Fully automated decision-making
– Profiling with Legal Consequences
– Right to Human Intervention

9.1 How to Do It
Contact : dpo@esentiara.com
Object : [GDPR] Type of request
Attachment : Copy of ID

9.2 Response Times
1 month from the date of receipt (extendable to 2 months if the case is complex)

9.3 Free of Charge
Free, except for requests that are clearly abusive or excessive

9.4 Reasoned Denial
In the event of a denial, an explanation of the reasons and available remedies

10.1 Technical Measures
Encryption : SSL/TLS for transmission, AES-256 for storage
Authentication : Multi-factor authentication for privileged access
Backups : Daily, quantified, tested
Monitoring : 24/7 monitoring, anomaly detection
Update : Automatic security patches

10.2 Organizational Measures
Training : Staff trained in GDPR and cybersecurity
Access : Principle of Least Privilege
Audits : Quarterly safety inspections
Procedures : Treatment Documentation
Incident : Response Plan and 72-Hour Notification

11.1 Notification to Authorities
No later than 72 hours after discovery (Art. 33 of the GDPR)

11.2 Notification of Individuals
Without delay if there is a high risk to your rights and freedoms (Art. 34 of the GDPR)

11.3 Violation Log
Documentation: All documented and archived violations

12.1 Essential Cookies (Exempt)
User Session : Keep me logged in
Shopping Cart : Temporary backup
Safety : CSRF Protection
Preferences : Language, currency

12.2 Analytical Cookies (With Consent)
Google Analytics : Audience measurement (anonymized IP)
Hotjar : User Behavior Analysis
Duration : 13 months maximum

12.3 Marketing Cookies (With Consent)
Facebook Pixel : Retargeting
Google Ads : Campaign Optimization
Revocable : At any time via settings

12.4 Management
Cookie management tool available at all times

13.1 Minimum Age
Age of consent: 16 (GDPR)

13.2 Parental Consent
Mandatory for children under 16

13.3 Verification
Sworn Statement at the Time of Registration

14.1 Prior contact
Step 1 : dpo@esentiara.com

14.2 Control authority
EU Countries: By Usual Place of Residence

14.3 Time Limit
There is no deadline for filing a claim

15.1 Right to Make Changes
Reserved for legal or technical changes

15.2 Information
Email + website notification

15.3 Objection
Right to close your account in the event of a disagreement

Data Protection Officer:

Email : dpo@esentiara.com
Address : SanaSarah LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, USA
Hours : Monday–Friday, 9 a.m.–6 p.m. (CET)
Languages : French, English, Spanish

This privacy policy complies with the General Data Protection Regulation (GDPR)
EU 2016/679.

Design sans titre (14)