Privacy policy

Last updated: February 19, 2026

The website www.boutique.mansa.fr (hereinafter “the Site”) is published by the MISSION DE PRÉFIGURATION DE MANSA-MAISON DES MONDES AFRICAINS (hereinafter “the Publisher” or “the Data Controller”), a public interest group, registered under SIREN number 929 381 820, with its registered office located at 182 Rue Saint-Honoré, Ministry of Culture, 75001 Paris, France, represented by its director, Ms. Elisabeth GOMIS.

The Publisher places great importance on protecting the data and privacy of the Site’s users (hereinafter “the User” or “the Users”).

The purpose of this Privacy Policy is to explain how, as the Data Controller, we collect Users’ personal information when they access, view, and use the Site, for what purposes, and for how long.

This data is collected solely for specific, explicit, and legitimate purposes.

The Data Controller reserves the right to amend this Privacy Policy and will notify the User of any updates.

1.Data Protection Officer

The Data Controller has appointed an internal Data Protection Officer (hereinafter “the DPO”), who can be contacted at the following email address: dpo@mansa.fr

2.What personal data is collected?

Personal data refers to any information that can be used to identify a natural person, either directly or indirectly.

In connection with the Website and related services, including MansA Boutique, the following categories of data may be collected:

  • Technical and connection data: IP address, session identifiers, and browsing data necessary for the security and proper functioning of the Site.
  • Identification information: first name(s), last name, email address, phone number (optional), required for managing forms, customer relations, and, if applicable, creating a customer account.
  • Contact and correspondence information: the content of a message submitted via a form or by email, as well as any additional documents or information provided by the User.
  • Purchase-related data: mailing address, billing and shipping information, order and transaction history. Payment data is processed directly by the secure payment provider PayZen, and the Publisher does not have access to it.
  • Newsletter-related data: the email address of the User who has requested to receive updates.

This data is strictly limited to what is necessary for the purposes for which it is collected.

3.When is users' personal data collected?

As the Data Controller, we collect Users’ personal data in the following cases:

  • Browsing the Website regarding IP addresses;
  • Create a customer account to place an order or manage your profile;
  • Placing an order for the information required for processing and delivery;
  • Submission of a message via the contact form, including first name(s), last name, email address, phone number, and message content;
  • Sign up for the newsletter using your email address.

All collection of personal data is carried out with the User’s explicit consent when necessary, or based on the Publisher’s legitimate interest (fraud prevention, transaction security, order management).

4.What is the purpose of processing the personal data collected?

The collection of personal data is intended, in particular, to:

  • the provision and improvement of the Site and the services provided;
  • personalizing the user experience on the Site;
  • the management, preparation, shipping, and tracking of orders placed on the Site.
  • the management of public service missions entrusted to the Publisher;
  • managing audience engagement;
  • managing information related to its events and communications;
  • managing newsletter subscriptions and sending out emails;
  • the conduct of studies, audits, and statistical analyses;
  • compliance with its legal obligations.

This data may not be used subsequently for purposes incompatible with these purposes.

For each data processing operation, the Data Controller undertakes to collect and process only the data strictly necessary for the purposes pursued.

The table below summarizes the various uses of Users' personal data and the legal bases on which their processing is based.

Personal informationObjectivesLegal Basis
IP address• Ensure the security of the
website • Prevent misuse or malicious activity
• Legitimate interest
Email address• Sending newsletters to users who have subscribed
• Responding to inquiries submitted by users via the contact form or by email
• User Consent
First and last name• Identifying the contact person and verifying their identity
• Tailoring responses to user requests
• Order management and billing
• Legitimate interest: used to prevent identity theft
• User consent
Phone number(optional)• Enable quick and appropriate communication with the User
• Identity verification, if necessary
• Order tracking and delivery
• User consent
• Legitimate interest: used for the purpose of preventing identity theft
Shipping and billing address• Order management, preparation, tracking, and delivery
• Customer account management and purchase history
• Performance of the contract
Payment information (via PayZen / Lyra Collect)• Secure payment processing
• Transaction and invoice management
• Performance of the contract
Message content• Reviewing and analyzing the User’s request in order to provide an appropriate response• User Consent
Order History and Preferences• Personalization of the shopping experience
• Loyalty program management
• Sending tailored offers, promotions, or communications
• Legitimate interest
• User consent

The cookies used on the Site are set by the Publisher or by third parties and are governed by a cookie policy,which can be accessed here.

5.Who are the recipients of Users' personal data? 

Users' personal data may be disclosed or made available:

  • To the Publisher’s authorized personnel, in the course of their duties.
  • To subcontractors working on behalf of the Publisher, such as:
    • The web hosting provider O2Switch;
    • The payment service provider PayZen;
    • Service providers responsible for sending the newsletter or compiling statistics.
  • To the competent administrative or judicial authorities, in the event of a legal request.
  • To law enforcement agencies, in connection with criminal investigations.

These recipients are contractually bound to maintain confidentiality and comply with applicable laws.

6. On what legal basis(es) is personal data processed?

Personal data is processed by the Data Controller on the basis of a legitimate interest or the User’s consent to the processing of their personal data for one or more specific purposes described in this privacy statement, in accordance with Article 5(1)(d) of Regulation (EU) 2018/1725. 

7.How long do we retain personal data? 

Personal data is stored in a technically secure environment. 

The data processed by the Website and the Website itself are hosted in France by O2SWITCH, whose contact information is as follows:

O2SWITCH

SAS with capital of €100,000
RCS Clermont-Ferrand 510 909 807
APE Code 6311Z
VAT No.: FR 35 510 90 98 07
Registered office: Chemin des Pardiaux 63000 CLERMONT FERRAND – France.
Phone: 04.44.44.60.40

Users' personal data is retained for as long as necessary to fulfill the purposes for which it is used. These retention periods vary depending on the specific type of personal data, namely:

Types of personal dataShelf life
IP addressTwelve months from the last collection
Email addressUntil you unsubscribe from the newsletter
Contact information: last name, first name, phone number, and email address3 years from the date of contact with MansA via the contact form
Order-related data (billing, shipping)Statutory retention period, generally 10 years for accounting records.

If personal data is processed for multiple purposes—including email addresses—it will be retained until the expiration of the longest retention or archiving period applicable to the intended purpose.

At the end of the periods listed above, the personal data collected will either be deleted or anonymized.

8.User Rights:

In accordance with applicable law, Users have the following rights:

  • The right to withdraw consent to the processing of personal data at any time where such processing is based on consent, without affecting the lawfulness of processing carried out prior to such withdrawal (right to withdraw consent – Article 7(3) of the GDPR);
  • The right to obtain confirmation as to whether or not personal data concerning the individual is being processed and, where it is, access to such personal data as well as to various details regarding the processing carried out by the Data Controller (right of access – Article 15 of the GDPR);
  • The right to have inaccurate personal data concerning the data subject corrected (right to rectification – Article 16 of the GDPR);
  • The right to request that the Data Controller erase personal data concerning the data subject in the cases provided for by law (right to erasure – Article 17 of the GDPR). The Data Controller may object to the erasure of personal data, in particular for legitimate and compelling reasons or when the personal data is necessary for the establishment, exercise, or defense of legal claims.
  • The right to restrict processing in the cases provided for by law (right to restriction of processing – Article 18 of the GDPR);
  • The right to receive the personal data provided by the User, in a structured, commonly used, and machine-readable format, and/or to request that the Data Controller transmit such data to another data controller, where the processing is based on consent or on a contract and the processing is carried out by automated means (right to data portability – Article 20 of the GDPR);
  • The right not to be subject to a decision based solely on automated processing that produces legal effects concerning the User or similarly significantly affects the User (right not to be subject to an automated individual decision – Article 22 of the GDPR) – the processing carried out by the Data Controller is not affected because such automated decisions within the meaning of the aforementioned Article 22 are not made by the Data Controller.

The User has the legal right to establish advance directives regarding the handling (retention, deletion, and disclosure) of their personal data in the event of death. It is the User’s responsibility (Article 85 of Law No. 78-17 of January 6, 1978) to:

  • either to establish general guidelines regarding all personal data and register them with a trusted third party certified by the CNIL;
  • or to provide the Data Controller with specific instructions regarding the handling of their personal data by designating a trusted third party responsible for ensuring compliance with these instructions, to whom the Data Controller will communicate them once the third party has identified themselves to the Data Controller. In the absence of such instructions, the heirs shall have this right. To this end, they must produce the certificate of inheritance establishing their status as heirs and any document proving their identity.

In the absence of advance directives or unless otherwise specified in such directives, the heirs of the person concerned may, after his or her death, exercise the rights set forth in this section to the extent necessary for the administration and settlement of the deceased’s estate.

9.How can you exercise your rights?

To exercise their rights, Users may contact the DPO by email at the following address: dpo@mansa.fr

If no response is received within one month, the User may file a complaint with the French Data Protection Authority (CNIL) on its website or via the following link:https://connexion.services.cnil.fr/.