Skip to main content

Privacy

Privacy policy

This document is intended to inform visitors to the Félicie website about how their personal data is collected, used and protected.

Data controller

Félicie, a simplified joint-stock company registered under number 849 084 314 with the Lille Métropole trade and companies register, represented by Louis Thorel, publication director. Address: 78 rue du Maréchal Foch, 59120 Loos, France. Email: clients@felicie-restaurant.com — Phone: +33 3 20 48 23 85. No data protection officer has been appointed: requests are handled directly at this address.

Data collected

We collect data that you voluntarily provide through forms (name, email, phone, message, etc.). Newsletter sign-up: we store your email address, the language of the site and the date of the sign-up, which stands as proof of your consent. The IP address used to sign up is recorded long enough to prevent abuse, then erased after 24 hours. Private event enquiry: we store the details you enter (name, company, email, phone, type of event, date, number of guests, message), the language of the site and the IP address of the submission, which is likewise erased after 24 hours. They are used solely to handle your enquiry and never for the newsletter. Audience measurement: we count page views without keeping either your IP address or your browser details. Counting relies on an anonymous fingerprint computed with a key that changes daily and is kept for only 48 hours; beyond that, nothing can link a visit to a person. If your browser sends an opt-out signal, no measurement takes place. Two signals are honoured: the older “Do Not Track” and “Global Privacy Control”, which has replaced it — several browsers, including Firefox, Brave and DuckDuckGo, let you switch it on in their privacy settings, and an extension provides it on the others. The refusal is applied by our server, not merely by your browser: nothing is recorded. What you have to provide, and what is optional. Browsing the site requires no data at all. For the newsletter, only your email address is needed: without it, signing up is impossible, and that is the only consequence of declining. For a private event enquiry, your name, email address and message are needed for us to reply; company, phone, type of event, date and number of guests are optional and merely help us prepare a more precise proposal. Leaving them out has no other consequence.

Purposes and legal bases

Data is used to: respond to your enquiries, manage reservations and private events, send the newsletter if you have consented, and measure site traffic in order to improve it. Each processing activity rests on a specific legal basis: — Newsletter: your consent (Article 6(1)(a) GDPR), given by submitting the form and withdrawable at any time. — Private event enquiry: steps taken at your request prior to entering into a contract (Article 6(1)(b)) — a quotation request is the stage that precedes a possible contract. — Audience measurement: our legitimate interest (Article 6(1)(f)) in knowing how much the site is visited in order to improve it. That interest is pursued with data limited to plain counting, with no tracker stored on your device and no advertising purpose whatsoever, which keeps the impact on your privacy to a minimum. — Logging in to the restaurant’s administration area: our legitimate interest in protecting access to the data entrusted to us. Statistics are produced for our own use only: they are shared with no one, are not used to track you across websites, and are never used to build a profile or to send you advertising. They are kept apart from our other processing: nothing you type into a form appears in them, and no statistic carries your name. Submitting a form is counted too, but separately: its fingerprint is computed with a key of its own, distinct from the one used for page views. The two therefore cannot be matched against each other, and the enquiry you send us, which carries your name, points to none of your visits. The IP address recorded when you submit is, in addition, erased after 24 hours. No automated decision-making and no profiling take place: nothing we process produces a decision about you without human involvement.

Retention

An automatic purge runs when the site starts, then once a day: the periods stated here are the ones the site actually applies. — Private event enquiries: 3 years from the date they reach us, for commercial follow-up. — Newsletter subscribers: until you unsubscribe, then 3 more years as proof of the consent given, before permanent deletion. — IP addresses recorded when a form is submitted (newsletter, private events): 24 hours, long enough to prevent abuse, then erased on the next run of the daily purge. The rest of the enquiry is kept. — Log of logins to the administration area: 6 months. Expired sessions are deleted every day. — Data used by the mechanism that limits how many forms can be submitted: 24 hours. — Traffic data, which is already anonymous: 396 days, that is 13 months. The key used to compute the fingerprints is kept for only 48 hours.

Your rights

Under the GDPR, you have the right to access, rectify, erase, restrict, object to and port your data. You can exercise these rights by writing to the email address shown above. You may withdraw your consent to the newsletter at any time, as easily as you gave it: every message contains an unsubscribe link, which leads to the “/desinscription” page and takes effect immediately; an email to the address above works just as well. Withdrawing does not affect messages already sent. You may also give general or specific directives on what should become of your data after your death (Article 85 of French Act No. 78-17 of 6 January 1978). Send them to the address above and we will follow them. If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr).

Cookies and trackers

This website sets no cookies when you visit it. There is therefore no consent banner to display. (Only the restaurant’s administration area, which is not part of the public website, uses a strictly necessary login cookie.) A single preference is stored in your browser (local storage): the light/dark mode, initialised from your system setting and changeable with one click. It never leaves your device, cannot identify you and disappears if you clear the site’s data. The display language is not stored: it depends solely on the address of the page you are viewing. The site relies on no third-party service to render: our typefaces are hosted on our own server. No data is therefore sent to an outside provider merely because you visited. There are two exceptions, both of them entirely up to you: neither loads without a click on your part. First, gift card purchases are handled by Gift Up, which processes the payment. Their module loads only if you click “Buy a gift card”; it then sets its own cookies, handles payment details under its own privacy policy, and may carry measurement tools from Meta (Facebook) and Google. Until you click, nothing is loaded. Second, the full list of our guest reviews is displayed by a module from Zenchef, our booking service. It loads only if you click “Read all Zenchef reviews”; it may then set its own cookies and process your data under Zenchef’s own privacy policy. The reviews shown on the home page are fetched by our own server, so displaying them creates no connection from your browser to Zenchef.

Recipients, transfers and security

Your data is neither sold, rented nor exchanged. It is accessible to the restaurant’s management and, on our behalf, to the following providers: — OVH SAS (France) hosts the website and its database: all the data recorded by the site is therefore stored there. — Zenchef (France) handles bookings and collects our guests’ reviews. Booking a table takes you to their service, where their own privacy policy applies. — Gift Up sells and manages the gift cards, and Stripe processes the payment. The details you enter for a purchase are collected directly by them, inside their module and under their own policy: we never see your card details. — Resend (United States) is intended to deliver our emails, but the service is not switched on to date: no message goes through it. The Gift Up module may also carry measurement tools from Meta (Facebook) and Google. We have not verified this ourselves yet and would rather tell you out of caution: that module loads only after you click “Buy a gift card”, and never otherwise. Transfers outside the European Union: the website, its database and everything you send us directly are hosted in France. Stripe and Resend, however, are established in the United States, and the country in which Gift Up is established has yet to be confirmed: buying a gift card therefore, in all likelihood, involves a transfer outside the European Union. We prefer to say so rather than claim a safeguard we have not verified: the exact framework of these transfers is being checked with each of these providers, and this page will be updated as soon as it is settled. Security: the publisher implements appropriate technical and organisational measures to protect your data against loss, unauthorised access or disclosure.

Last updated: 5 September 2026.

For the legal information of this site, please read the Legal notice.