House of Seraphine
Last updated: May 31, 2026
1. Identity of the Data Controller
House of Seraphine (hereinafter: "House of Seraphine", "we", "us" or "our") respects your privacy and processes personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Belgian privacy legislation.
Data Controller
Company name: House of Seraphine
Address: Driekerkenstraat 75 8501 Bissegem
Company number: BE0780889293
Email: elynne.kathy.ponseele@gmail.com
2. What personal data do we collect?
Depending on your interaction with our website or services, we may process the following personal data.
Identification data
-
First and last name
-
Company name
-
Billing and delivery address
-
Email address
-
Phone number
Financial data
-
Billing information
-
Payment status
-
Transaction details
Note: House of Seraphine never stores full credit card details. Payments are processed through certified payment providers.
Website data
-
IP address
-
Browser data
-
Device data
-
Cookie identifiers
-
Browsing behavior on our website
Communication data
-
Contact form submissions
-
Email traffic
-
Customer service requests
-
Social media posts
Marketing data
-
Newsletter subscriptions
-
Marketing preferences
-
Newsletter open and click behavior
3. Purposes of processing
House of Seraphine processes personal data exclusively for specified and legitimate purposes and based on an applicable legal basis as provided for in the AVG/GDPR.
Performance of contracts
Personal data may be processed for:
-
Processing orders
-
Delivering products
-
Providing customer service
-
Warranty handling
-
Return processing
Legal basis: performance of the contract.
Legal obligations
Personal data may be processed for:
-
Accounting
-
Invoicing
-
Fulfilling tax obligations
-
Fraud prevention
Legal basis: legal obligation.
Direct marketing
Personal data may be processed for:
-
Newsletters
-
Promotions
-
Product updates
-
Personalized offers
Legal basis: consent or legitimate interest, to the extent permitted under applicable law.
You can unsubscribe at any time via the unsubscribe link in each newsletter. If the processing is based on consent, you can withdraw this consent at any time.
Website analysis and optimization
Personal data may be processed for:
-
Analysis of the use of our website
-
Performance measurement
-
Improvement of the user experience
Legal basis: consent for analytical cookies, insofar as such consent is legally required.
4. Retention periods
House of Seraphine does not retain personal data longer than is necessary for the purposes for which it was collected, unless a legal obligation requires a longer retention period.
| Type of data | Retention period |
|---|---|
| Customer data | Up to 10 years after the last purchase |
| Invoices | 10 years |
| Contact requests | 2 years |
| Newsletter data | Until unsubscribed |
| Cookie data | Maximum 13 months |
If applicable legal obligations prescribe a longer retention period, this statutory retention period will be observed.
5. Recipients of personal data
House of Seraphine may share personal data with carefully selected external service providers when this is necessary for the performance of our services or legal obligations.
This may include:
-
Hosting providers
-
Payment providers
-
Accounting software
-
Shipping companies
-
Email marketing platforms
-
IT service providers
These parties only receive the personal data necessary for the performance of their specific services.
Where required, House of Seraphine concludes a data processing agreement with these service providers in accordance with Article 28 GDPR.
6. International data transfers
If personal data is processed outside the European Economic Area (EEA), House of Seraphine ensures that this transfer only takes place in accordance with the applicable regulations on international transfers of personal data.
This may include:
-
To countries for which an adequacy decision of the European Commission applies; or
-
Based on appropriate safeguards, such as the standard contractual clauses approved by the European Commission.
7. Security
House of Seraphine takes appropriate technical and organizational measures to protect personal data against loss, destruction, unauthorized access, alteration or other forms of unlawful processing.
These measures may include:
-
SSL/TLS encryption
-
Access control
-
Strong password protection
-
Regular software updates
-
Backups
-
Restricted access to personal data based on necessity
Although House of Seraphine takes appropriate security measures, no method of electronic storage or data transfer can guarantee complete security.
8. Your rights
In accordance with the GDPR, you have the following rights, subject to applicable conditions and exceptions:
-
The right to access your personal data
-
The right to rectification of inaccurate personal data
-
The right to erasure of data
-
The right to restriction of processing
-
The right to data portability
-
The right to object to certain processing activities
-
The right to withdraw consent when processing is based on consent
Requests regarding your privacy rights can be sent to:
Email: [to be filled in]
House of Seraphine processes such requests in accordance with applicable legal deadlines. In principle, a response will be provided within one month of receipt of the request. If necessary, this period may be extended in accordance with the GDPR.
9. Complaints
If you believe that House of Seraphine is not processing your personal data in accordance with applicable privacy legislation, we ask you to first contact us so that we can investigate the situation.
You also have the right to lodge a complaint with the competent supervisory authority.
For Belgium, this is:
Data Protection Authority (GBA)
Drukpersstraat 35
1000 Brussels
Belgium
COOKIE POLICY
What are cookies?
Cookies are small text files that can be stored on your computer, smartphone, tablet, or other device when you visit a website.
Cookies can be used, among other things, to ensure the operation of the website, remember preferences, collect visitor statistics, and, if permitted, support marketing purposes.
What cookies do we use?
Essential cookies
These cookies are necessary for the proper functioning of our website and may be used for:
-
Shopping cart functionality
-
Security
-
Website functionality
-
Technical functionalities
Insofar as these cookies are strictly necessary for the service requested by the user, no prior consent is required.
Functional cookies
Functional cookies may be used to remember certain visitor preferences, including:
-
Language settings
-
User preferences
-
Login status
These cookies contribute to a user-friendly website experience.
Analytical cookies
Analytical cookies help House of Seraphine understand the use and performance of the website, for example with regard to:
-
Visitor behavior
-
Page performance
-
Website improvements
Example:
-
Google Analytics, if used
Analytical cookies are only placed, when legally required, after consent has been obtained.
Marketing cookies
Marketing cookies may be used for:
-
Personalized advertisements
-
Remarketing
-
Social media integrations
-
Measuring advertising campaigns
Examples of possible services include:
-
Meta Pixel
-
Google Ads
-
TikTok Pixel
Marketing cookies are only placed if the required consent has been obtained.
Cookie management
During your first visit to our website, a cookie banner may be displayed allowing you to manage your cookie preferences.
You can change or withdraw your consent at any time, in accordance with the options made available through our website.
The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
NEWSLETTER POLICY
When you subscribe to the House of Seraphine newsletter:
-
we ask for your explicit consent, where required;
-
we record, where relevant, the date, time, and source of subscription;
-
we store your email address as long as you remain subscribed to the newsletter.
You can unsubscribe at any time via the unsubscribe link at the bottom of each newsletter.
After unsubscribing, your newsletter data will be deleted or anonymized, unless a legal obligation or a legitimate interest justifies further retention.
DATA PROCESSING AGREEMENT — TEMPLATE
This data processing agreement applies between House of Seraphine (hereinafter: "Data Controller") and any external service provider that processes personal data on behalf of House of Seraphine (hereinafter: "Processor").
1. Subject matter
The Processor processes personal data exclusively on behalf of House of Seraphine and in accordance with House of Seraphine's written instructions, subject to differing legal obligations.
2. Obligations of the Processor
The Processor:
-
processes personal data exclusively according to written instructions from House of Seraphine;
-
ensures the confidentiality of personal data;
-
takes appropriate technical and organizational security measures;
-
reports a personal data breach to House of Seraphine without undue delay;
-
does not engage sub-processors without the required consent or prior authorization;
-
supports House of Seraphine in fulfilling its obligations under the AVG/GDPR;
-
cooperates, insofar as reasonably necessary, with requests from data subjects;
-
provides the information necessary to demonstrate compliance with applicable privacy legislation.
3. Security
The Processor takes appropriate technical and organizational measures to protect personal data against, among other things:
-
loss;
-
unauthorized access;
-
destruction;
-
alteration;
-
unauthorized disclosure;
-
other forms of unlawful processing.
4. Termination of the agreement
Upon termination of the services, the Processor will, at House of Seraphine's choice and to the extent legally permitted:
-
delete all personal data; or
-
return all personal data to House of Seraphine.
This applies unless a legal obligation requires the Processor to retain certain personal data further.
DATA BREACH PROCEDURE
In the event of a suspected data breach or other personal data breach, House of Seraphine will take the following steps.
1. Register incident
The incident is registered as soon as possible and available information is collected.
2. Perform risk analysis
House of Seraphine assesses the nature of the incident, the personal data involved, the number of individuals affected, and the potential consequences for data subjects.
3. Notification to the supervisory authority
If legally required, a notification is made to the competent supervisory authority within the applicable legal deadline. If circumstances require it, a notification should generally be made within 72 hours of becoming aware of the breach.
4. Inform data subjects
If the breach is likely to result in a high risk to the rights and freedoms of data subjects, the affected individuals will be informed in accordance with applicable regulations.
5. Corrective measures
House of Seraphine takes appropriate measures to:
-
limit the consequences of the incident;
-
determine the cause of the incident;
-
prevent further incidents;
-
improve security measures where necessary.
6. Documentation
The incident and the measures taken are documented in accordance with applicable legal obligations.
House of Seraphine
This policy is periodically evaluated and, if necessary, adjusted to changes in business operations, technologies used, or applicable laws and regulations.