DORIS GROUP PRIVACY POLICY
In the frame of the operation of the website accessible website accessible at www.dorisgroup.com (the “Website“) and their activities (the “Activities“), DORIS Group and the entities of the Group DORIS (together “DORIS“) may collect and process personal data about you.
This personal data is processed by DORIS in accordance with French Data Act No. 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties, the European Regulation 2016/679 of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (“GDPR“), and any other legislation or regulation applicable to the protection of personal data (the “Data Regulation“).
The purpose of this Privacy Policy is to inform you about the way DORIS implement these personal data processing. If you have any questions about the processing of your personal data or wish to exercise your rights, please contact us in accordance with the information provided in the “contact” section below.
Article 1: Data processing implemented by DORIS
Data controllers:
DORIS Group, a société anonyme (limited liability company) headquartered at 58A rue du Dessous des Berges, 75013 Paris, France, with share capital of €3,559,424, registered in the Paris Trade and Companies Register (RCS Paris) under number 338 274 491, which publishes the Website, is the data controller for the processing of personal data relating thereto.
Other DORIS Group entities that conduct Activities are respectively data controllers for the processing of personal data that they handle in this context in accordance with the applicable pre-contractual or contractual framework. You are otherwise informed of such data processing.
Categories of personal data and data subjects:
When you consult the Website, the following personal data may be collected and processed by DORIS:
- Connection data or data relating to your use of the Website: such as the URL of the links through which you have accessed the Site or your Internet Protocol (IP) address;
- Identification and professional data when you fill in the online contact form: such as your surname, first name, email address or telephone number, the name of your company, as well as the content of your exchanges with DORIS;
- Professional data when you apply for a job;
- Data collected via cookies: Page counter; visitor tracking and tracing (anonymized); analysis of website navigation behavior (anonymized)
During the Activities, depending on your status and your interactions with DORIS, the following personal data may be collected and processed:
· Identification data: such as your surname, first name, gender, telephone number, email address, postal address, date and place of birth, nationality;
· Professional data: such as your professional details, company, mandate or positions held, diploma, accreditation;
· Administrative, financial, commercial or fiscal content: such as administrative or official documents, banking or economic data, the content of messages and interactions with DORIS;
· Data relating to Activities concerning you: such as data relating to the monitoring and management of your pre-contractual, contractual and commercial relationship with DORIS, the organisation and management of projects, the management of any disputes or litigation or the conduct of investigations or surveys.
This personal data may be collected about you or about your company’s employees, agents or legal representatives, and you undertake to inform them of this, as well as of the content of this Privacy Policy.
We do not collect or process sensitive data. Exceptionally, DORIS may, for the purposes of preparing and managing certain projects, collect and process sensitive data, such as health data, only if it is strictly necessary for the performance of a contract, as part of a project or to comply with a legal obligation, which you will be otherwise informed.
Purposes of the data processing
Depending on your interactions with DORIS and the categories of personal data concerned, data may be collected and processed:
- To improve the user experience on the Website;
- To enable DORIS to evaluate and follow the number of visits to the Website;
- To enable DORIS to contact the person who has filled in the online contact form or to apply for a job;
- To provide pre-contractual or technical information that you may request from DORIS;
- To participate to a call for tenders, execute a contract or provide services in the frame of the Activities;
- To satisfy the legitimate interests of DORIS such as managing commercial relations with its prospects and clients (answering a question, sending commercial offers, etc.);
- To comply with the law, regulations, and legal requests and orders applicable to DORIS.
Legal basis for processing personal data
Depending on the purposes set out above and the applicable Regulations, your personal data are processed by DORIS on the basis of:
- the legitimate interests of DORIS (Article 6 (1) f) GDPR);
- your consent (Article 6 (1) GDPR);
- the performance of pre-contractual or contractual measures (Article 6(1) b GDPR); or
- to comply with a legal obligation to which DORIS is subject (Article 6(1) c GDPR).
Data processing conditions
DORIS collects and processes your personal data in compliance with the applicable Data Regulation:
· For specified, explicit and legitimate purposes, and not further processed in a way incompatible with those purposes: in accordance with the purpose limitation principle;
· Only personal data that is adequate, relevant and limited to what is necessary for the purposes for which it is processed: in accordance with the principle of data minimisation.
Data retention periods
Your personal data is stored by DORIS for the period necessary to achieve the purposes described above, except in cases where (i) you request DORIS to delete it before the expiration of this period, subject to the conditions imposed by applicable law, and/or (ii) the law permits or requires it to be kept for a longer period.
Purposes | Data retention periods |
Management of commercial relations | 3 years from your last interaction with DORIS |
Performance of services, execution of a contract | Up to 15 years from the end of the service or contract concerned |
Accounting and financial purposes | 10 years from the end of the service or contract concerned |
Recruitment management | 2 years from the date of your last interaction with DORIS |
Management of requests to exercise rights | 6 years from the end of the last interaction in this context |
However, your personal data may be stored by DORIS for a longer period for evidential purposes in accordance with the applicable prescription periods or a proportionate legitimate interest.
Storage conditions
Every precaution is taken to ensure the security and confidentiality of your personal data, in particular to prevent their loss, alteration, destruction or use by unauthorised third parties.
Transfer and recipients of your personal data
Personal data may be accessible to DORIS’ internal teams (to ensure the proper functioning of the Website and manage the relationship with users and clients, for example), as well as to DORIS service providers (in particular our technical service providers) or third parties for legal reasons (for example to judicial or public authorities, if required by law, or regulated professions such as lawyers, notaries or auditors).
Where strictly necessary for the purposes of managing the Website or operating the Activities, personal data may be transferred outside the European Union, in particular to non-EU entities of the Doris Group. When your personal data is transferred outside the European Union, these transfers are governed by the mechanisms provided for by the RGPD and validated by the European Commission, such as the Standard Contractual Clauses, a copy of which you may request (see the “Contact” section below).
Data subjects’ rights
In the conditions provided for by the Data Regulation, you have the following rights with regard to your personal data:
· Rights of access, rectification, updating, deletion and restriction: you may request access to your personal data held and processed by DORIS, consult them, obtain a paper or electronic copy and request their correction, updating, deletion or restriction in the cases provided for by the Data Regulation;
· Right to object: you may, under the conditions and within the limits provided for by the Data Regulation, object to the processing of your personal data by DORIS. In certain conditions, exercising your right to object may lead to a change in the way we provide our services or in the way the Website operates, if your personal data is required for this purpose;
· Right to portability: in the cases provided for in the Data Regulation, you can also exercise your right to the portability of your personal data;
· Complaint to a data protection authority: without prejudice to any other legal remedy, you have the right to lodge a complaint with the data protection authority of the European Union country in which you reside, work or in which you consider that your rights with regard to your personal data have been violated.
You may exercise your rights as described above by sending a request to the contact details given in the “Contact” section below. DORIS may ask you for any proof of your identity.
Contact
All requests relating to the processing of personal data should be sent to dpo@dorisgroup.com.
Modification of the Privacy Policy
DORIS reserves the right to make changes to the Privacy Policy at any time. In the event of a substantial change, we will inform you of the update.