INTRODUCTION
This privacy policy is intended to explain, clearly and transparently, how we collect, use and process your personal data, as well as the measures implemented to ensure its security and confidentiality, in accordance with Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and the applicable regulations.
This privacy policy applies to the personal data of data subjects, including in particular: users of the website and associated platforms, clients, prospects, suppliers, partners, specifiers, representatives of professional or institutional organisations, as well as any person involved in professional or institutional relationships, including applicants for job vacancies.
The controller of personal data is EUROVENT CERTITA CERTIFICATION (ECC), whose registered office is located at 34 rue Laffitte, 75009 Paris. The contact details of the Data Protection Officer are as follows: dpo@eurovent-certification.com
This privacy policy may be amended at any time to take account of legal, regulatory or operational developments. In the event of a substantial change, data subjects will be informed by any appropriate means, in particular via the website or associated platforms.
DATA COLLECTED
We collect personal data relating to clients, prospects, applicants for job vacancies, and users of the website and associated platforms.
With regard to clients, the data processed includes in particular the professional contact details of contacts within their organisation (such as first and last name, telephone number, job title, and email or postal address). These data are processed for the purposes of managing the contractual relationship and monitoring the services provided. In this respect, the processing carried out includes in particular contract management, invoicing, monitoring of services, compliance with accounting, tax and regulatory obligations, and, where applicable, the management of complaints and disputes. Banking data relating to the legal or natural person being invoiced may also be processed, in compliance with legal and regulatory obligations and in order to ensure payment for the services. Finally, additional information may be collected when it is voluntarily provided by the relevant contacts, insofar as it is necessary for the proper performance of the services.
With regard to suppliers, partners, specifiers, representatives of professional or institutional organisations, and more generally contacts involved in professional or institutional relationships, the data processed includes in particular professional contact details (such as first and last name, job title, organisation, email and postal addresses, and professional telephone numbers). These data are processed for the purposes of managing contractual or pre-contractual relationships, monitoring collaborations, and developing and maintaining the company's professional network. They may also be used in the context of sectoral, institutional or regulatory exchanges related to its activities.
With regard to prospects, the data processed includes in particular professional contact details (such as first and last name, position held within the organisation, and email and postal addresses).
These data are processed for the purposes of commercial prospecting, sending information relating to the services offered, invitations to professional events, and institutional communication.
With regard to applicants for job vacancies, the data processed includes in particular contact details (such as first and last name and email address), as well as the information contained in the curriculum vitae and cover letter submitted as part of an application. These data are processed for the purposes of managing the recruitment process and assessing the suitability of applications for the positions offered.
With regard to users of the website and associated platforms, the data processed includes in particular the information necessary to handle requests submitted by users, such as first name, last name and email address.
These data are processed for the purposes of handling requests submitted via contact forms, improving the operation and performance of the website, carrying out statistical analysis of its traffic, and securing access to online services.
ECC does not make any decision producing legal effects or significantly affecting a person solely on the basis of automated processing.
LEGAL BASES FOR PROCESSING YOUR DATA
The processing of personal data carried out by ECC is based on the following legal bases:
- performance of the contract: management of contractual relationships with clients, provision of services and invoicing;
- pre-contractual measures and legitimate interest: management of applications and organisation of the recruitment process. The assessment of an application for a specific position is based on the performance of pre-contractual measures taken at the applicant's request. The retention of an application in order to offer other professional opportunities at a later date is based on ECC's legitimate interest in building a pool of applicants, subject to the rights and interests of the data subjects;
- compliance with legal and regulatory obligations: retention of accounting documents, compliance with tax obligations and disclosure of data to the competent authorities where required by law;
- legitimate interest: management of pre-contractual relationships, professional prospecting to B2B contacts, institutional communication, and management and defence of the company's rights;
- consent: sending electronic communications where required by regulations and use of certain cookies subject to prior consent.
INTERNATIONAL TRANSFERS
Certain service providers or suppliers of digital solutions used by ECC, including solutions incorporating artificial intelligence features, may be established outside the European Economic Area or process data outside it. In such cases, ECC ensures that these transfers are governed in accordance with the GDPR, in particular by means of an adequacy decision, standard contractual clauses adopted by the European Commission, or any other appropriate safeguard provided for by the applicable regulations.
The list of countries concerned and a copy or description of the applicable safeguards may be obtained from the DPO.
DATA COLLECTION
Personal data are collected either directly from data subjects or indirectly from publicly accessible professional sources. These sources may include, for example, professional directories, company websites or professional social networks (such as LinkedIn). When using the website and associated platforms (in particular the ECC website, the client portal and certain interfaces used as part of the services provided), cookies strictly necessary for their operation may be placed on the user's device.
The purpose of these cookies is to ensure the proper operation of the services, user authentication and load balancing. They are not used for advertising or targeting purposes. Users may configure their browser to refuse all or some cookies. However, refusing certain cookies may result in reduced access to certain features of the services concerned.
In connection with certain electronic communications, ECC may use technologies that make it possible to measure message openings or interactions with their content. Where required by applicable regulations, such processing is based on the prior consent of the data subject, which may be withdrawn at any time.
DATA RECIPIENTS
In accordance with applicable regulations, personal data may be disclosed, strictly to the extent necessary, to the following categories of recipients:
- the relevant internal departments (in particular those responsible for recruitment, administrative management, invoicing, certification activities, operations and communication), as well as persons directly involved in processing certification files;
- law firms acting as advisers or in defence of the company's interests, in particular in connection with compliance with legal and regulatory obligations or the management of disputes;
- service providers, partners and subcontractors acting on behalf of the company (such as IT service providers, hosting providers, support services, translation or communication providers), within the limits of their assignments and subject to contractual confidentiality and security obligations;
- competent administrative, judicial or regulatory authorities, where required by law or at the request of an authorised authority.
Data are disclosed only to the extent necessary to achieve the purposes pursued and in compliance with Regulation (EU) 2016/679.
DATA SECURITY
The company implements appropriate technical and organisational measures to ensure the security and confidentiality of the personal data processed and to protect them against any accidental or unlawful destruction, loss, alteration, disclosure or unauthorised access.
RETENTION PERIOD
Personal data are retained for periods no longer than necessary in relation to the purposes for which they are processed, in compliance with applicable regulations. Accordingly:
- applicants' data are retained for a maximum period of 2 years from the last contact;
- client data are retained for the duration of the contractual relationship and then archived in accordance with applicable legal obligations (in particular 5 years for contractual matters and 10 years for accounting matters);
- prospects' data are retained for a maximum period of 3 years from the last contact;
- data collected via the website, in particular through contact forms, are retained for the period necessary to process the request and then archived for a maximum period of 3 years from the last contact;
- Les données relatives aux fournisseurs, partenaires et contacts professionnels sont conservées pendant la durée de la relation, puis pendant la durée nécessaire au respect des obligations légales et à la constatation, à l’exercice ou à la défense de droits en justice ;
- les cookies sont conservés pour une durée maximale de 13 mois, conformément aux recommandations de la CNIL ;
- technical logs and connection data used to ensure the security of information systems, detect anomalies and prevent fraudulent access are retained for a maximum period of 12 months from the date they are recorded, unless they need to be retained for longer due to a security incident, dispute or applicable legal obligation.
EXERCISE OF YOUR RIGHTS REGARDING YOUR PERSONAL DATA
In accordance with Regulation (EU) 2016/679 (GDPR), you have rights in relation to personal data concerning you, including after they have been provided to the company. In particular, you may:
- object at any time, on grounds relating to your particular situation, to processing based on legitimate interest. Where processing is carried out for direct marketing purposes, this right may be exercised without giving a reason;
- withdraw your consent at any time where processing is based on it, without affecting the lawfulness of processing carried out previously;
- access the data concerning you and obtain a copy of them, subject to the limitations provided for by regulations;
- request the rectification of inaccurate or incomplete data;
- request the erasure of your data under the conditions provided for by regulations, in particular where they are no longer necessary or have been unlawfully processed;
- request restriction of processing in the cases provided for by regulations, in particular where the accuracy of the data is contested or where you object to the processing;
- benefit from data portability where processing is based on consent or on a contract and is carried out by automated means;
- provide instructions regarding what should happen to your data after your death.
If you consider that the processing of your personal data does not comply with applicable regulations, you may lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL).
To exercise your rights or withdraw your consent, you may contact EUROVENT CERTITA CERTIFICATION at the following address: dpo@eurovent-certification.com A response will be provided as soon as possible and, in any event, within one month.