Privacy Policy
At Blonde Angel Baby (the “Website”), accessible at https://blondeangelbaby.com, we respect your privacy and are committed to protecting the personal data you provide to us. This Privacy Policy explains what data we collect, for what purposes, on what legal basis, and what rights you have.
This policy has been prepared in accordance with:
- The General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), applicable to users located in the European Economic Area (EEA) and the United Kingdom.
- Applicable privacy law in the United States, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), other state privacy laws, and applicable federal law.
Please read this policy carefully before providing your data through the Website.
1. Data Controller
The party responsible for processing your personal data is:
- Controller: Start & Power LCC
- Contact email: info@blondeangelbaby.com
- Website: https://blondeangelbaby.com
For any questions relating to the processing of your data or to this policy, you may contact us at the email address above.
2. Personal Data We Collect
We only process data that you voluntarily provide to us or that is generated while you browse. Specifically:
2.1 Contact Form Data
When you use the contact form, we collect:
- Name or pseudonym
- Email address
- The content of the message you choose to send us
2.2 Newsletter Subscription Data
If you subscribe to our newsletter, we collect:
- Email address
- Name (if requested by the subscription form)
2.3 Browsing, Analytics, and Cookie Data
While you browse, we may collect, through cookies and similar technologies:
- IP address
- Browser and device type and version
- Operating system
- Pages visited, time spent, and browsing behavior
- Traffic source (referrer)
Details of the cookies we use, their purpose, and their duration are described in our Cookie Policy.
3. Purposes of Processing
We process your personal data for the following purposes:
- Responding to your inquiries and communications: to manage and respond to the requests you send us through the contact form or by email.
- Sending the newsletter and communications: to send you news, articles, and content from the Website, provided you have subscribed in advance.
- Analyzing and improving the Website: to compile usage statistics, understand user behavior, and improve our content and browsing experience.
- Advertising: to display ads, including, where applicable, personalized advertising managed by third-party platforms, in accordance with your preferences and applicable law.
4. Legal Basis for Processing (EEA and UK Users)
For users subject to the GDPR, the legal basis that allows us to process your data depends on the purpose:
- Consent of the data subject (Art. 6(1)(a) GDPR): this is the basis for handling your inquiries through the contact form, sending the newsletter, and placing non-essential analytics and advertising cookies. You may withdraw your consent at any time without affecting the lawfulness of processing prior to its withdrawal.
- Legitimate interest of the controller (Art. 6(1)(f) GDPR): to ensure the security of the Website, prevent fraudulent use, and carry out basic statistical analysis for its proper functioning, provided that such interest does not override your rights and freedoms.
5. Data Retention
We will retain your personal data only for as long as necessary to fulfill the purposes described:
- Contact form data: for the time needed to handle and respond to your request and, thereafter, for the periods legally required to address potential liabilities. Once those periods expire, the data will be deleted.
- Newsletter subscription data: until you unsubscribe or withdraw your consent. Each communication includes a link to unsubscribe easily.
- Browsing and cookie data: for the specific retention periods of each cookie, as detailed in the Cookie Policy.
6. Data Recipients
We do not sell your personal data for monetary consideration. However, in order to provide our services, we may share data with the following recipients:
6.1 Service Providers (Processors)
- Web hosting provider: OVH
- Email marketing platform: None
- Google LLC: through Google Analytics, for statistical analysis of Website usage, and, where applicable, Google AdSense to manage advertising.
- Advertising platforms and affiliate networks: to manage ads and affiliate links.
Each of these providers processes data in accordance with its own privacy policies and the data processing agreements entered into with the controller.
6.2 International Data Transfers
Some of our providers (such as Google) may process data on servers located in the United States or other countries outside the EEA. Where this involves an international transfer from the EEA or the United Kingdom, it is carried out with appropriate safeguards under the GDPR, such as adherence to the EU-U.S. Data Privacy Framework or the use of Standard Contractual Clauses approved by the European Commission.
7. Your Privacy Rights
7.1 EEA and UK Users (GDPR)
If you reside in the EEA or the United Kingdom, you have the following rights:
- Access: to know what personal data of yours we are processing.
- Rectification: to request the correction of inaccurate or incomplete data.
- Erasure (“right to be forgotten”): to request the deletion of your data when, among other reasons, it is no longer necessary.
- Objection: to object to the processing of your data in certain circumstances.
- Restriction of processing: to request that the processing of your data be restricted in the cases provided by law.
- Portability: to receive your data in a structured, commonly used, and machine-readable format, or to request its transmission to another controller.
- Withdrawal of consent: to withdraw consent at any time, without retroactive effect.
You also have the right to lodge a complaint with the competent supervisory authority in your country of residence if you believe that the processing of your data does not comply with applicable law.
7.2 United States Users (CCPA/CPRA and Other State Laws)
If you reside in California or another state with applicable privacy legislation, you may exercise, subject to the terms and exceptions set out in that legislation, the following rights:
- Right to know / access: to know the categories and specific pieces of personal information we collect, the sources, the purposes, and the categories of third parties with whom it is shared.
- Right to delete: to request the deletion of the personal information we have collected about you.
- Right to correct: to request the correction of inaccurate personal information.
- Right to opt out of the “sale” or “sharing” of personal information: to direct us not to “sell” or “share” your personal information, as those terms are defined under the CCPA/CPRA (which may include the use of advertising cookies for cross-context behavioral advertising).
- Right to limit the use of sensitive personal information.
- Right to non-discrimination: you will not receive discriminatory treatment for exercising any of these rights.
To exercise the right to opt out, you may use the “Do Not Sell or Share My Personal Information” link available on the Website [TO COMPLETE — confirm link or method] or contact us through the means indicated below. Residents of other U.S. states with privacy laws may have similar rights.
8. How to Exercise Your Rights
To exercise any of the rights described above, send a request to [TO COMPLETE — email], indicating the right you wish to exercise. We may ask you to verify your identity to ensure that only you can access your information. Exercising these rights is free of charge. We will respond to your request within the time frames established by applicable law.
9. Cookies and Tracking Technologies
The Website uses first-party and third-party cookies for technical, analytics, and advertising purposes. You can find detailed information and manage your preferences in our Cookie Policy and through the cookie settings panel available on the Website. Many browsers and advertising platforms also allow you to disable or limit tracking cookies.
10. Marketing Communications and Newsletter
We will only send you email communications if you have voluntarily subscribed. In accordance with applicable law, including the U.S. CAN-SPAM Act, all of our communications identify the sender, do not use deceptive headers, and include a simple, free mechanism to unsubscribe. You may cancel your subscription at any time using the link included in each message or by contacting us at the email above.
11. Security Measures
We implement appropriate technical and organizational measures to ensure a level of security suited to the risk, in order to protect your personal data against loss, misuse, unauthorized access, disclosure, alteration, or destruction. However, no system is completely secure, so we cannot guarantee absolute security of the information.
12. Minors
The Website and its content are intended exclusively for persons aged 18 or over. We do not knowingly collect data from minors and, in particular, we do not collect information from children under 13, in accordance with the Children’s Online Privacy Protection Act (COPPA). If we become aware that we have received data from a minor without the appropriate authorization, we will delete it.
13. Accuracy of Data
As a user, you warrant that the data you provide is truthful, accurate, and up to date, and you agree to notify us of any changes. You will be responsible for any false or inaccurate information you provide and for any resulting harm.
14. Changes to This Privacy Policy
We may amend this Privacy Policy to adapt it to legislative developments or changes in our processing practices. Any changes will be published on this page, so we recommend reviewing it periodically. The date of the last update is indicated at the end of this document.