Privacy policy
Last updated: 26 August 2026.
QR GROUPE processes its business customers' personal data in accordance with Regulation (EU) 2016/679 and the French Data Protection Act.
Data controller
QR GROUPE, 99 Avenue Aristide Briand, 68200 Mulhouse. Email: contact@qrgroupe.fr. Telephone: 07 68 87 44 89.
Data collected
The business contact's identity and details, company name, SIRET number, delivery and billing addresses, order and invoice history, and where applicable the geolocation of the delivery address used to calculate carriage.
Bank details are never collected or stored by QR GROUPE: online payment is handled by Stripe, a PCI-DSS certified provider.
Purposes and legal bases
Managing accounts, orders, deliveries and invoicing rests on performance of the contract. Keeping invoices rests on a legal obligation. Fraud prevention and service security rest on legitimate interest.
Retention periods
Account data is kept for the duration of the commercial relationship, then three years from the last contact. Invoices and accounting records are kept ten years, under article L123-22 of the French Commercial Code.
Recipients
Data is intended for QR GROUPE's own staff and its processors: MongoDB Atlas (database hosting), IONOS (site hosting), Brevo (email delivery), Stripe (online payment). No data is sold or passed on for advertising.
Your rights
You have rights of access, rectification, erasure, restriction, objection and portability. Exercise them at contact@qrgroupe.fr. You may also delete your account from the customer area; invoices already issued are then kept under accounting obligations, and other data is anonymised.
You may lodge a complaint with the Commission nationale de l'informatique et des libertés, 3 place de Fontenoy, 75007 Paris.
Cookies
The site sets only cookies strictly necessary for it to work: keeping you signed in, remembering the language and holding the basket. These are exempt from consent under article 82 of the French Data Protection Act. No advertising or third-party analytics cookie is used.
Security
Traffic is encrypted over HTTPS. Passwords are stored as irreversible hashes. Access to administration data is restricted to authorised accounts.