Privacy Policy
Effective date: 07 September 2025
1. Who we are
Balimassage (sole proprietorship of Saleg Lona) — SIRET 89099817200039, APE 9604Z.
Contact: balitreatments@gmail.com
Hosting provider: Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus — hostinger.com/contact
2. Scope
This Policy explains how we collect, use and protect personal data when you use our website balimassage.org, create an account, contact us, or participate in our loyalty program.
3. Data we collect
- Identity & contact data: name, email, phone (if provided), account ID.
- Account & loyalty data: points balance and history (processed via WordPress plugins such as Ultimate Member / myCred).
- Communications: messages you send us (e.g., contact form, email).
- Technical data: IP address, device/browser info, pages viewed, cookies (see our Cookie Policy).
- Payments: we do not store payment card data on our servers. If online payment is offered, it is processed by a third-party provider according to its own privacy terms.
4. Purposes & legal bases (GDPR)
- Provide the service & manage your account/loyalty: perform a contract or pre-contractual steps.
- Customer support & communications: legitimate interest to respond to requests.
- Site security, fraud prevention, logs: legitimate interest and/or legal obligation.
- Analytics & improvements: legitimate interest and/or consent where required (for non-essential cookies).
- Legal compliance: accounting, regulatory requirements.
5. Cookies & similar technologies
We use essential cookies to run the site and (subject to your consent where required) analytics or functional cookies. For details and choices, see our Cookie Policy.
6. Sharing of data
- Service providers (processors): hosting (Hostinger), WordPress plugins and technical providers strictly for operating the site.
- Legal disclosures: where required by law or to protect our rights.
We do not sell your personal data.
7. International transfers
Some providers may process data outside the EEA. When this occurs, we use appropriate safeguards (e.g., European Commission Standard Contractual Clauses) to protect your data.
8. Retention
- Account & loyalty data: kept while your account is active and then archived or deleted within a reasonable period.
- Communication records: typically up to 3 years after last contact (or longer where required for evidence).
- Invoicing/accounting data: kept up to 10 years (legal obligation in France).
9. Your rights (EU/UK GDPR)
You may request access, rectification, erasure, restriction or portability of your data, and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time.
You can also lodge a complaint with a supervisory authority. In France: CNIL.
10. Security
We apply technical and organizational measures appropriate to the risks (HTTPS, access controls, backups). No method of transmission or storage is 100% secure.
11. Children
Our services are intended for adults. If you believe a child has provided personal data, please contact us so we can delete it.
12. Contact
For any privacy request, contact: balitreatments@gmail.com.
13. Changes to this Policy
We may update this Policy from time to time. Significant changes will be indicated on this page. Please review it periodically.
This document is provided for general information only and does not constitute legal advice.
Related pages: Terms & Conditions · Cookie Policy · Contact