1. Introduction
CJRM Studio LLC (hereinafter "Norvio", "we", "us") places particular importance on protecting your personal data. This policy describes how we collect, use, store and protect the personal data you entrust to us through the norvio.fr website and the associated services.
We are committed to complying with the General Data Protection Regulation (GDPR — EU Regulation 2016/679), which applies to any processing of personal data of European Union residents, regardless of where our company is established.
2. Data Controller
- CJRM Studio LLC — operating under the Norvio brand
- Address: 30 N Gould St Ste N, Sheridan, WY 82801, United States
- Tax identification number (EIN): 32-0856307
- GDPR contact: contact@norvio.fr
- EU representative: not appointed — pursuant to Article 27(2)(a) of the GDPR, the processing carried out through the Site is occasional, does not involve sensitive data and does not present a high risk to the rights and freedoms of data subjects.
3. Data Collected
We collect the following data:
3.1 Data provided voluntarily (contact form)
- First and last name
- Email address
- Phone number
- Company or business (optional)
- Project type, desired timeline, free-text message
3.2 Data collected automatically (browsing)
- IP address (anonymised)
- Browser type and operating system
- Pages viewed, visit duration, traffic source
- Technical and audience-measurement cookies (see Cookie Policy)
4. Purposes & Lawful Bases
- Responding to your contact / quote request — Lawful basis: performance of pre-contractual measures (Art. 6(1)(b) GDPR)
- Managing the client relationship and delivering contractual services — Lawful basis: performance of a contract
- Issuing invoices and meeting our accounting obligations — Lawful basis: legal obligation (Art. 6(1)(c) GDPR)
- Improving the Site (anonymised browsing statistics) — Lawful basis: legitimate interest (Art. 6(1)(f) GDPR)
- Sending you marketing communications (newsletter, offers) — Lawful basis: consent (Art. 6(1)(a) GDPR), only where you have explicitly consented
5. Recipients & Processors
Your data is strictly reserved for CJRM Studio LLC. It is never sold, rented or transferred to third parties for commercial purposes.
We use technical processors for the operation of the Site, which may process your data on our behalf:
- Site hosting — Hostinger International Ltd (Lithuania, EU)
- Contact form service — Formspree Inc. (USA, Data Privacy Framework certified)
- Payment service — Stripe Inc. (USA, Data Privacy Framework certified, PSD2 compliant)
- Analytics tools — no third-party tracking tool is currently used. Should Google Analytics or an equivalent be added, this policy will be updated.
All our processors are selected for their GDPR compliance and sign data processing agreements (DPAs).
6. Transfers Outside the EU
As CJRM Studio LLC is a US company, some of your data may be transferred to and stored in the United States. These transfers are governed by:
- The EU-US Data Privacy Framework (July 2023)
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Technical and organisational security measures (encryption, anonymisation)
7. Retention Periods
- Contact requests that did not lead to a project: 3 years from the last exchange
- Active clients: for the entire duration of the business relationship + 5 years thereafter
- Invoices and accounting obligations: 10 years (legal obligation)
- Audience-measurement cookies: 13 months maximum
- Anonymised browsing data: 25 months maximum
8. Your Rights
In accordance with the GDPR, you have the following rights over your data:
- Right of access (Art. 15) — to know what data is held about you
- Right to rectification (Art. 16) — to correct inaccurate data
- Right to erasure (Art. 17) — to request the deletion of your data
- Right to restriction (Art. 18) — to restrict the processing of your data
- Right to data portability (Art. 20) — to retrieve your data in a structured format
- Right to object (Art. 21) — to object to the processing at any time
- Right to withdraw your consent at any time (for processing based on consent)
- Right to set post-mortem directives regarding the fate of your data after your death
To exercise these rights, contact us: contact@norvio.fr. We will respond within 30 days at most (Art. 12 GDPR).
You also have the right to lodge a complaint with the CNIL (the French supervisory authority): cnil.fr
9. Security
We implement appropriate technical and organisational measures to protect your data against loss, destruction, unauthorised access, alteration or disclosure:
- TLS/SSL encryption for all communications
- Secure storage with compliant hosting providers (ISO 27001, SOC 2)
- Data access restricted to authorised personnel
- Regular encrypted backups
- Periodic security audits
10. Changes to This Policy
We reserve the right to amend this policy at any time to reflect legal, technical or operational developments. The date of the last update is shown at the top of this page. We encourage you to review it regularly.
11. Contact
For any question regarding this policy or to exercise your rights:
- Email: contact@norvio.fr
- Phone: +33636439592
- Form: Contact page