Politique de confidentialité

PRIVACY POLICY

Last Updated: September 8, 2026

1. INTRODUCTION

This Privacy Policy ("Policy") describes how the operator of this website (the "Website," "we," "us," or "our") collects, uses, discloses, stores, and protects personal data belonging to visitors, customers, and other users ("you," "your," or "Users") of our online store specializing in women's watches, marketed and sold primarily to customers located in France, Germany, and other member states of the European Union and the European Economic Area ("EEA"), as well as to customers in other jurisdictions who choose to shop with us.

We are committed to protecting your privacy and handling your personal data in an open, transparent, and lawful manner. This Policy is intended to comply with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the "General Data Protection Regulation" or "GDPR"), the French Data Protection Act (Loi Informatique et Libertés), the German Federal Data Protection Act (Bundesdatenschutzgesetz, "BDSG"), the ePrivacy Directive (2002/58/EC) as implemented into the national law of EU member states, and, where applicable, other data protection and privacy laws of jurisdictions in which we operate or from which we accept customers.

By accessing or using our Website, by creating an account, by placing an order, or by otherwise providing us with your personal data, you acknowledge that you have read and understood this Policy. If you do not agree with the terms of this Policy, please do not use our Website or provide us with your personal data.

This Policy applies regardless of the device or platform you use to access our Website (desktop, mobile, tablet, or otherwise) and regardless of the country from which you access it.

2. DATA CONTROLLER AND CONTACT INFORMATION

For the purposes of the GDPR and other applicable data protection laws, the entity responsible for determining the purposes and means of the processing of your personal data (the "Data Controller") is:

Business Contact Address:
Estrada Vitor Luiz Jantsch
Paverama, Rio Grande do Sul
CEP 95865000
Brazil

Email: contact@minoran.com

If you have any questions, concerns, or requests regarding this Policy or our data processing practices, or if you wish to exercise any of the rights described in Section 10 below, you may contact us at the email address provided above. We will endeavor to respond to all legitimate requests within one (1) month, as required under Article 12(3) of the GDPR, and we will inform you if we require additional time due to the complexity or number of requests.

Because our business is established outside of the European Union but we offer goods to individuals located in the Union and monitor the behavior of such individuals (for example, through analytics and marketing cookies), we are subject to the GDPR pursuant to Article 3(2). Where required under Article 27 of the GDPR, we will designate, or will inform you of, a representative established in the Union who may be contacted in addition to, or instead of, us on all issues related to the processing of your personal data, in order to ensure compliance with this Regulation. If no such representative is currently designated, you may direct all inquiries to the contact details above, and this Policy will be updated to reflect any Article 27 representative appointed in the future.

3. SCOPE OF THIS POLICY

This Policy applies to all personal data we collect through:

  1. Our Website and any subdomains thereof;
  2. Any mobile applications we may operate;
  3. Any social media pages, accounts, or business profiles that we control and that link to this Policy;
  4. Any marketing communications, newsletters, or promotional materials we send to you;
  5. Customer service interactions conducted via email, live chat, telephone, or any other communication channel;
  6. Any offline interactions connected to an online transaction (for example, telephone orders placed with customer service, or returns processed at a physical partner location, if applicable).

This Policy does not apply to third-party websites, applications, or services that may be linked from our Website, including payment processors, shipping carriers, and social media platforms, each of which maintains its own separate privacy policy. We encourage you to review the privacy policies of any third-party service before providing your personal data to it.

4. DEFINITIONS

For the purposes of this Policy, and consistent with Article 4 of the GDPR, the following definitions apply:

"Personal Data" means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

"Processing" means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.

"Data Subject" means the identified or identifiable natural person to whom personal data relates — that is, you, our customer or website visitor.

"Data Controller" means the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data.

"Data Processor" means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Data Controller.

"Third Party" means any natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

"Consent" means any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

"Special Categories of Personal Data" means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation.

5. CATEGORIES OF PERSONAL DATA WE COLLECT

We collect several categories of personal data depending on how you interact with our Website. These categories include, without limitation:

5.1 Identity Data

Full name, title, date of birth (where relevant, for example for age verification or promotional eligibility), gender or salutation preference (where voluntarily provided).

5.2 Contact Data

Billing address, shipping/delivery address, email address, telephone number, country of residence.

5.3 Financial and Transaction Data

Details about payments to and from you, including partial payment card information as permitted under PCI-DSS standards (note: full payment card numbers are never stored on our servers — see Section 8 below), order history, purchase amounts, refund and return history, invoice details, and VAT or tax identification numbers where applicable (for business customers).

5.4 Account Data

Username, password (stored in encrypted/hashed form), account preferences, wish lists, saved items, order tracking preferences, and communication preferences.

5.5 Technical Data

Internet Protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device identifiers, and other technology on the devices you use to access our Website.

5.6 Usage Data

Information about how you use our Website, our products, and our services, including pages visited, time spent on pages, click-through data, referral source, search queries entered on our Website, and cart abandonment data.

5.7 Marketing and Communications Data

Your preferences in receiving marketing communications from us and our third parties, your communication preferences, and your history of engagement with our marketing (opens, clicks).

5.8 Profile Data

Your purchases or orders, your interests, preferences, feedback, and survey responses, and inferred preferences regarding watch styles, materials, or price ranges based on your browsing and purchase behavior.

5.9 Location Data

General geographic location inferred from your IP address, and, if you consent, more precise location data if you use location-based features of our Website or app.

5.10 Correspondence Data

Records of correspondence if you contact us, including via email, contact forms, live chat transcripts, and telephone call notes.

5.11 Special Categories of Data

We do not intentionally collect any special categories of personal data (as defined in Section 4 above) from you. We ask that you do not submit any such data to us through contact forms, product reviews, customer service correspondence, or otherwise. If you voluntarily provide such data, you consent to our processing it strictly for the purpose for which it was provided, and we will take appropriate measures to protect it.

5.12 Aggregated Data

We may aggregate and/or anonymize Usage Data or other data for statistical or research purposes, such that it can no longer be used to identify you, either on its own or in combination with other data. Aggregated Data is not considered personal data under this Policy because it does not directly or indirectly reveal your identity.

6. HOW WE COLLECT YOUR PERSONAL DATA

We use different methods to collect data from and about you, including through:

a) Direct Interactions. You may give us your Identity, Contact, and Financial Data by filling in forms, creating an account, placing an order, subscribing to our newsletter, requesting marketing be sent to you, entering a promotion or survey, or corresponding with us by post, phone, email, live chat, or otherwise.

b) Automated Technologies or Interactions. As you interact with our Website, we may automatically collect Technical Data and Usage Data about your equipment, browsing actions, and patterns. We collect this data using cookies, server logs, pixel tags, and other similar technologies, as further described in our Cookie Policy (Section 12 below).

c) Third Parties or Publicly Available Sources. We may receive personal data about you from various third parties, including:

  • Technical Data from analytics providers such as Google Analytics (based outside the EU);
  • Technical Data from advertising networks such as Meta (Facebook/Instagram) Ads and Google Ads (based outside the EU);
  • Contact, Financial, and Transaction Data from payment and delivery service providers such as Shopify Payments, Stripe, PayPal, and shipping/logistics carriers (which may be based inside or outside the EU);
  • Identity and Contact Data from publicly available sources.

7. LEGAL BASES FOR PROCESSING (GDPR ARTICLE 6)

We only process your personal data where we have a valid legal basis for doing so under Article 6(1) of the GDPR. Depending on the specific purpose, we rely on one or more of the following legal bases:

7.1 Performance of a Contract (Art. 6(1)(b))

We process your Identity, Contact, and Financial Data to fulfill our contractual obligations to you, such as processing and delivering your order, handling payments, managing your account, and providing customer service related to a purchase you have made or intend to make.

7.2 Legitimate Interests (Art. 6(1)(f))

We process certain data where necessary for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests. Our legitimate interests include: improving and developing our Website and product offerings; preventing fraud and ensuring network and information security; conducting direct marketing to existing customers regarding similar products (subject to your right to object, see Section 10.6); understanding customer behavior through analytics; enforcing our legal rights; and managing our business operations, including accounting and audits. Where we rely on legitimate interests, we have conducted (or will conduct upon request) a balancing test to ensure our interests do not unjustifiably override your rights and freedoms.

7.3 Consent (Art. 6(1)(a))

We rely on your consent for: sending you marketing communications where you are a new prospective customer (as required under French and German implementations of the ePrivacy Directive); placing non-essential cookies and similar tracking technologies on your device (see Section 12); and any other processing activity for which we specifically request your consent through an opt-in mechanism. Where processing is based on consent, you have the right to withdraw that consent at any time, free of charge, without affecting the lawfulness of processing carried out prior to withdrawal.

7.4 Legal Obligation (Art. 6(1)(c))

We process certain data to comply with legal obligations to which we are subject, including tax and accounting obligations, obligations under consumer protection law, responding to lawful requests from public authorities, and complying with customs and import/export regulations applicable to cross-border shipment of goods from Brazil to the EU.

7.5 Vital Interests (Art. 6(1)(d))

We do not anticipate processing your data on this basis, but reserve the right to do so in rare circumstances necessary to protect your vital interests or those of another natural person.

8. HOW WE USE YOUR PERSONAL DATA

We use your personal data only for the purposes for which we collected it, which principally include:

  1. To register you as a new customer;
  2. To process, confirm, and deliver your order, including arranging international shipment from Brazil to France, Germany, or other destination countries, and handling associated customs documentation;
  3. To manage our relationship with you, including notifying you about changes to our terms or this Policy;
  4. To process and administer returns, exchanges, refunds, and warranty claims on watches purchased;
  5. To administer and protect our business and Website, including troubleshooting, data analysis, testing, system maintenance, support, reporting, and hosting of data;
  6. To deliver relevant Website content and advertisements to you and measure or understand the effectiveness of advertising we serve to you;
  7. To use data analytics to improve our Website, products, marketing, customer relationships, and experiences;
  8. To make suggestions and recommendations to you about goods that may be of interest to you, based on your prior purchases or browsing habits;
  9. To send you marketing communications, where you have opted in or where otherwise permitted by applicable law, and to allow you to participate in promotions, contests, or surveys;
  10. To detect, investigate, and prevent fraudulent transactions and other illegal activities, and to protect the rights and property of our business, our customers, and third parties;
  11. To comply with applicable tax, customs, accounting, and other legal or regulatory obligations in Brazil, the European Union, and any other relevant jurisdiction.

Regarding payment card data specifically: we do not directly store full payment card numbers, card verification values (CVV), or similar sensitive payment credentials on our own servers. Payment processing is handled by PCI-DSS-compliant third-party payment processors (such as Shopify Payments, Stripe, or PayPal), who act as independent data controllers or as our processors with respect to the payment data they handle, subject to their own privacy policies.

We will not use your personal data for purposes that are materially different, unrelated, or incompatible with the purposes for which it was originally collected, unless we notify you first and, where required, obtain your consent.

9. INTERNATIONAL DATA TRANSFERS

Because our business operates from Brazil and serves customers primarily located in France, Germany, and other EU/EEA member states, your personal data will necessarily be transferred to, stored in, and processed in Brazil, a country outside the European Economic Area.

We are aware that, as of the date of this Policy, Brazil has not been the subject of a full adequacy decision from the European Commission covering all processing activities under Article 45 of the GDPR. Where we transfer your personal data outside the EEA to Brazil or to any other third country not covered by an adequacy decision, we ensure an appropriate level of protection is in place through one or more of the following safeguards, in accordance with Chapter V of the GDPR:

a) Standard Contractual Clauses (SCCs): We enter into the European Commission's Standard Contractual Clauses (as approved by Implementing Decision (EU) 2021/914) with the receiving entity, which impose contractual data protection obligations equivalent to those under the GDPR.

b) Supplementary Measures: Where necessary following a transfer impact assessment, we implement additional technical, organizational, and contractual safeguards, such as encryption of data in transit and at rest, pseudonymization where feasible, and strict access controls.

c) Brazil's LGPD: We note that Brazil has its own comprehensive data protection framework, the Lei Geral de Proteção de Dados (LGPD, Law No. 13,709/2018), which shares many principles with the GDPR, including data minimization, purpose limitation, and data subject rights, and we process personal data in compliance with the LGPD as well as the GDPR to the extent both apply.

d) Derogations for Specific Situations (Art. 49 GDPR): In limited circumstances, we may rely on derogations such as your explicit consent to the proposed transfer, after having been informed of the possible risks, or because the transfer is necessary for the performance of a contract between you and us (for example, to ship your order to you).

We also transfer personal data to processors and sub-processors located in other third countries (including the United States), such as certain cloud hosting providers, email service providers, and analytics or advertising platforms. Where such transfers occur, we ensure equivalent safeguards are in place, such as SCCs or reliance on a valid EU-U.S. Data Privacy Framework certification, where applicable to the specific processor.

You may request further information about the specific safeguards we have implemented with respect to your personal data, including a copy of the relevant Standard Contractual Clauses, by contacting us using the details in Section 2.

10. YOUR RIGHTS UNDER THE GDPR

If you are located in the EU/EEA (or otherwise benefit from GDPR protections), you have the following rights with respect to your personal data, subject to certain exceptions and limitations set out in the GDPR:

10.1 Right of Access (Art. 15)

You have the right to obtain confirmation as to whether we process personal data concerning you, and, where that is the case, access to that personal data and to specific information about the processing (such as purposes, categories of data, recipients, retention period, and the existence of your other rights).

10.2 Right to Rectification (Art. 16)

You have the right to obtain, without undue delay, the rectification of inaccurate personal data concerning you, and to have incomplete personal data completed, including by means of providing a supplementary statement.

10.3 Right to Erasure / "Right to be Forgotten" (Art. 17)

You have the right to obtain the erasure of your personal data without undue delay where one of the following grounds applies: the data is no longer necessary for the purposes for which it was collected; you withdraw consent on which the processing was based and there is no other legal ground; you object to the processing and there are no overriding legitimate grounds; the data has been unlawfully processed; or erasure is required to comply with a legal obligation. This right is not absolute — we may retain data as necessary to comply with a legal obligation (such as tax or accounting retention requirements) or to establish, exercise, or defend legal claims.

10.4 Right to Restriction of Processing (Art. 18)

You have the right to obtain restriction of processing where: you contest the accuracy of the data (for a period enabling us to verify accuracy); the processing is unlawful and you oppose erasure and request restriction instead; we no longer need the data but you require it for the establishment, exercise, or defense of legal claims; or you have objected to processing pending verification of whether our legitimate grounds override yours.

10.5 Right to Data Portability (Art. 20)

Where processing is based on consent or on a contract and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us.

10.6 Right to Object (Art. 21)

You have the right to object, on grounds relating to your particular situation, to processing based on our legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for legal claims. You have an absolute and unconditional right to object at any time to the processing of your personal data for direct marketing purposes, including any profiling related to such direct marketing, and we will cease such processing promptly upon your objection, free of charge.

10.7 Rights Related to Automated Decision-Making and Profiling (Art. 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We confirm that we do not currently use fully automated decision-making that produces legal or similarly significant effects on our customers. We may use limited profiling (for example, to recommend products based on browsing history), but such profiling does not result in decisions with legal or similarly significant effects and does not occur on a solely automated basis without the possibility of human review upon request.

10.8 Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing based on consent before its withdrawal.

10.9 Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA member state of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR. In particular:

  • If you reside in France, you may contact the Commission Nationale de l'Informatique et des Libertés (CNIL) at www.cnil.fr;
  • If you reside in Germany, you may contact the data protection authority of your federal state (Landesdatenschutzbehörde), a list of which is maintained by the Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) at www.bfdi.bund.de;
  • If you reside in another EU/EEA member state, you may contact your national data protection authority; a full list of EU supervisory authorities is available on the European Data Protection Board's website at edpb.europa.eu.

10.10 How to Exercise Your Rights

To exercise any of the above rights, please contact us at contact@minoran.com. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We will respond to your request within one month of receipt, which we may extend by a further two months where necessary, taking into account the complexity and number of requests; we will inform you of any such extension within one month of your original request. We do not charge a fee for exercising your rights unless your request is manifestly unfounded, repetitive, or excessive, in which case we may charge a reasonable administrative fee or refuse to act on the request.

11. DATA RETENTION

We retain your personal data only for as long as reasonably necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it, whether those purposes can be achieved through other means, and applicable legal, tax, customs, and accounting requirements. Specific retention periods include, as a general framework:

  • Account Data: retained for as long as your account remains active, and for a reasonable period thereafter (generally up to three years) in case you wish to reactivate your account, unless you request earlier deletion;
  • Order and Transaction Data: retained for the period required by applicable tax, customs, and commercial accounting laws, which in France and Germany is generally ten (10) years from the end of the relevant fiscal year, and comparable retention periods apply under Brazilian tax law;
  • Marketing Consent and Preference Data: retained until you withdraw consent or unsubscribe, and for a limited period thereafter to record and honor your opt-out choice;
  • Customer Service Correspondence: generally retained for up to three (3) years following resolution of your inquiry, to allow us to address any follow-up issues or legal claims;
  • Technical/Usage Data collected via cookies and analytics: retained in accordance with the specific retention periods set out in our Cookie Policy (Section 12), generally not exceeding thirteen (13) months for analytics cookies, in line with CNIL guidance;
  • Data relating to legal claims or disputes: retained for the duration of any relevant limitation period under applicable law, which may extend beyond the periods listed above.

Once the applicable retention period expires, we will securely delete, destroy, or anonymize your personal data such that it can no longer be associated with you, unless we are required or permitted by law to retain it for a longer period.

12. COOKIES AND SIMILAR TRACKING TECHNOLOGIES

12.1 What Are Cookies

Cookies are small text files placed on your device when you visit a website. They are widely used to make websites function more efficiently, as well as to provide information to the operators of the site. We also use similar technologies, including web beacons, pixel tags, local storage, and software development kits (SDKs) embedded in any mobile application (collectively referred to as "Cookies" in this Section).

12.2 Categories of Cookies We Use

a) Strictly Necessary Cookies. These cookies are essential to enable you to move around the Website and use its features, such as accessing secure areas, maintaining your shopping cart, and completing checkout. Without these cookies, services you have asked for (like remembering items in your basket) cannot be provided. Under the ePrivacy Directive as implemented in France and Germany, these cookies do not require your consent, though we still inform you of their use.

b) Performance and Analytics Cookies. These cookies collect information about how visitors use our Website, for instance which pages visitors go to most often, and if they receive error messages from web pages. These cookies do not collect information that identifies a visitor directly; all information these cookies collect is aggregated and therefore anonymous or pseudonymous. We use tools such as Google Analytics for this purpose. These cookies require your consent under applicable EU law.

c) Functionality Cookies. These cookies allow the Website to remember choices you make (such as your language preference or region) and provide enhanced, more personal features. These require your consent unless strictly necessary for a service you have explicitly requested.

d) Targeting/Advertising Cookies. These cookies are used to deliver advertisements more relevant to you and your interests, to limit the number of times you see an advertisement, and to help measure the effectiveness of advertising campaigns, including through platforms such as Meta (Facebook/Instagram) Pixel and Google Ads remarketing tags. These cookies require your explicit, opt-in consent.

12.3 Consent Management

When you first visit our Website, you will be presented with a cookie consent banner allowing you to accept or reject non-essential cookies, and to manage your preferences by category. In compliance with CNIL (France) and applicable German guidance implementing the ePrivacy Directive, we do not place non-essential cookies on your device until you have provided affirmative, granular consent, and we provide an easily accessible mechanism to withdraw your consent at any time, which is as simple as the mechanism used to give consent. Continuing to browse our Website without adjusting your cookie settings does not, by itself, constitute valid consent for non-essential cookies under EU law, and we have designed our consent mechanism accordingly.

12.4 Managing Cookies via Your Browser

In addition to the controls we provide, most web browsers allow you to control cookies through their settings. You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of our Website may become inaccessible or not function properly, including the ability to complete a purchase.

12.5 Do Not Track

Some browsers have a "Do Not Track" feature that lets you tell websites you do not want your online activities tracked. Because there is not yet an accepted standard for how to respond to such signals, our Website does not currently respond to Do Not Track browser signals, though we respect the cookie preferences you set through our consent management tool.

13. THIRD-PARTY DISCLOSURES AND RECIPIENTS OF PERSONAL DATA

We do not sell your personal data to third parties for monetary consideration. However, we do share your personal data with certain categories of third parties as necessary to operate our business, including:

a) Service Providers and Processors: Website hosting and e-commerce platform providers (e.g., Shopify); payment processors (e.g., Shopify Payments, Stripe, PayPal); shipping, logistics, and customs brokerage companies necessary to deliver watches internationally from Brazil to France, Germany, and other destinations; email marketing and customer relationship management (CRM) platforms; customer service and live chat software providers; analytics providers (e.g., Google Analytics); cloud storage and data backup providers.

b) Professional Advisers: Including lawyers, bankers, auditors, and insurers based in Brazil or elsewhere who provide consultancy, banking, legal, insurance, and accounting services.

c) Tax, Customs, and Regulatory Authorities: In Brazil, France, Germany, and other jurisdictions, where required for tax reporting, customs declarations, or regulatory compliance in connection with the cross-border sale and importation of goods.

d) Third Parties in Connection with a Business Transaction: If we sell or transfer all or part of our business or assets to a third party, or undergo a merger, acquisition, reorganization, or insolvency proceeding, personal data may be transferred to the relevant third party as part of that transaction, subject to appropriate confidentiality safeguards.

e) Legal and Safety Disclosures: We may disclose your personal data to the extent required by law, to comply with a subpoena, court order, or similar legal process, or when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.

Each third-party processor with whom we share personal data is bound by contractual obligations (including, where applicable, GDPR-compliant Data Processing Agreements under Article 28) to implement appropriate technical and organizational measures to protect your data, to process it only on our documented instructions, and to maintain confidentiality.

14. DATA SECURITY

We have implemented appropriate technical and organizational measures designed to protect the security of your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, in accordance with Article 32 of the GDPR. These measures include, without limitation:

  • Encryption of data in transit using Transport Layer Security (TLS/SSL) protocols;
  • Encryption or hashing of sensitive data such as account passwords;
  • Access controls limiting access to personal data to employees, contractors, and agents on a need-to-know basis, each of whom is subject to a duty of confidentiality;
  • Use of PCI-DSS compliant third-party payment processors, such that full payment card data does not pass through or reside on our own servers;
  • Regular review and testing of our security measures;
  • Procedures to deal with any suspected personal data breach, including notifying you and any applicable regulator (such as the CNIL, the relevant German Landesdatenschutzbehörde, or the Brazilian Autoridade Nacional de Proteção de Dados (ANPD)) of a breach where legally required to do so, which under Article 33 of the GDPR means notifying the competent supervisory authority without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to your rights and freedoms.

While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the internet or method of electronic storage is 100% secure, and we cannot guarantee absolute security.

15. CHILDREN'S PRIVACY

Our Website and products are intended for adults and are not directed at children. We do not knowingly collect personal data from individuals under the age of sixteen (16) (or such other minimum age required for valid consent under the law of the relevant EU member state, which may be as low as thirteen (13) in some member states pursuant to Article 8 of the GDPR) without appropriate parental or guardian consent. If we become aware that we have inadvertently collected personal data from a child without the requisite consent, we will take steps to delete such information as soon as reasonably practicable. If you believe we may have collected personal data from a child in violation of this Policy, please contact us immediately at contact@minoran.com.

16. YOUR CHOICES REGARDING MARKETING COMMUNICATIONS

You may ask us to stop sending you marketing messages at any time by clicking the "unsubscribe" link contained in any marketing email we send you, by adjusting your communication preferences in your account settings, or by contacting us at contact@minoran.com. Where you opt out of receiving marketing communications, this will not apply to personal data provided as a result of a product/service purchase, warranty registration, product/service experience, or other transactions, for which we may still contact you with transactional or service-related communications (such as order confirmations, shipping notifications, and responses to inquiries).

17. LINKS TO THIRD-PARTY WEBSITES

Our Website may include links to third-party websites, plug-ins, and applications, such as social media platforms. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our Website, we encourage you to read the privacy policy of every website you visit.

18. CHANGES TO THIS PRIVACY POLICY

We may update this Policy from time to time to reflect changes in our data practices, legal or regulatory requirements, or for other operational reasons. Any changes will be posted on this page with an updated "Last Updated" date at the top of this Policy. Where changes are material, and to the extent required by applicable law, we will provide you with more prominent notice, such as via email notification or a notice on our Website, and, where required by law, we will seek your renewed consent before applying such changes to previously collected data. We encourage you to review this Policy periodically to stay informed about how we are protecting your personal data.

19. GOVERNING LAW AND JURISDICTION FOR DATA PROTECTION MATTERS

Nothing in this Section is intended to limit any mandatory statutory rights you may have as a consumer or data subject under the law of your country of habitual residence, including your right to lodge a complaint with your local supervisory authority as set out in Section 10.9, and your right to bring proceedings before the courts of the EU/EEA member state where you have your habitual residence, in accordance with Article 79 of the GDPR, regardless of any general governing law provision that may appear in our separate Terms and Conditions of Sale.

20. CONTACT US

If you have any questions about this Privacy Policy, our data practices, or wish to exercise any of your rights described herein, please contact us at:

Email: contact@minoran.com

Postal Address:
Estrada Vitor Luiz Jantsch
Paverama, Rio Grande do Sul
CEP 95865000
Brazil

We take all inquiries and complaints regarding the handling of personal data seriously and will investigate and respond to legitimate concerns as promptly as possible.


This Privacy Policy was last reviewed and updated on September 8, 2026. It should be read in conjunction with our Terms and Conditions of Sale, Returns and Refunds Policy, and Cookie Policy, each of which is available on our Website.