PRIVACY NOTICE

Information Statement on the Protection of Personal Data

 

The members of the HESTIA consortium have installed functionality on its Internet site that leads to the processing of personal data. This information statement on the protection of personal data indicates how the members of the HESTIA consortium processes the personal data of people who subscribe to these services.

 

1. Definitions

Personal data: any information relating to an identified or identifiable natural person; a natural person who can be identified, directly or indirectly, is deemed to be an “identifiable natural person”.

 

2. Processing initiated based on the consent of the data subject

The types of processing listed below are based on consent:

a. Managing the delivery of news, newsletters and press releases

o   Legal basis: consent of the data subject

o   Data collected: Last name, First name, telephone, email, language of communication, HESTIA consortium activities and topics in which said person is interested

o   Recipients: administrators, authorized persons from the Communications Department and the IT security team.

b. Managing the accreditation of the graphic charter

o   Legal basis: consent of the data subject

o   Data collected: last name, first name, email address, language of communication, type and name of project, company involved in the project, log

o   Recipients: administrators, authorized persons from the Communications Department and the IT security team.

c. Contact form

o   Legal basis: consent of the data subject

o   Data collected:

§  Mandatory: email, subject and message,

§  Depending on the message and the recipient: offer number, user account, telephone, customer country, company name, part number,

o   Recipients: authorized persons from the Communications Department, person for whom the messages are intended, administrators and the IT security team.

 

3. Processing initiated based on the members of the HESTIA consortium’s legitimate interests

The members of the HESTIA consortium have installed functionality in order to protect the personal data of the persons concerned, to protect its information system and to comply with its legal obligations.

a. Securing the information system and the confidentiality of personal data

o   Legal basis: Legitimate interest: the members of the HESTIA consortium have implemented appropriate security and confidentiality measures to protect personal data against any loss, alteration or disclosure to unauthorized third parties. Its procedures comply with current best practice and are regularly updated.

o   Data collected: connection logs, cookies and IP address

o   Retention period: 1 year

o   Recipients: administrators and the IT security team.

b. Managing compliance with legal obligations and due-diligence obligations incumbent on the members of the HESTIA consortium ; managing their obligations to protect personnel; managing the rights of the members of the HESTIA consortium and those of others as well as assets and information

o   Legal basis: Legitimate interest: the members of the HESTIA consortium has installed functionality in order to ensure its compliance with international regulation, to defend its interests in a court of law or before an arbitrator, to manage the companies’ general operational activities, and to protect its staff, its assets and its information. Due diligence work carried out during negotiations for the sale or purchase of a company may involve sending personal data to the potential buyer or seller.

o   Data: any data necessary for the operation

o   Retention period: Data used in this regard is retained until the end of the operation concerned.

o   Recipients: persons authorized according to the operation

 

4. Information about the personal data collected

Personal data may be collected directly from the data subject by taking it from the form they complete or indirectly by taking it from his/her terminal.

The list of personal data collected may change in order to enable the members of the HESTIA consortium to comply with local regulations.

Information fields marked with an asterisk or marked as mandatory must be completed in order to create the account. If the data subject wishes his/her data to be deleted, they will no longer receive news emails, press releases or newsletters. Any bookings he/she has will be canceled.

Personal data cannot be reused for purposes that are incompatible with the initial purposes.

Under no circumstances do the members of the HESTIA consortium sell or transfer personal data to third parties for marketing or publicity purposes.

 

5. Transfers outside the European Union

Personal data is not transferred outside of the European Union.

 

6. Cookies

A cookie is a file that the visited site stores on the computer or on any peripheral used to browse the Internet, in order, for instance, to send session information for each page, or to record that a particular page has been accessed. The aim is to optimize browsing in terms of its convenience, efficiency and pertinence.

The information is stored in the cookie for a limited time. It is anonymous and relates to the pages visited and the time spent on each, the means used for browsing (operating system, browser and resolution, etc.), the searches made, and the IP address, in order to make rough groupings by geographical area etc.

For those affected, a module for managing cookie storage is available on the HESTIA Internet site.

 

7. Statement

In order to process someone’s personal data, he/she must agree to this Information Statement on personal data by ticking the box on the form used to create the account or the contact form.

The person concerned undertakes to provide complete, accurate and legitimate information in the form.

Please do not create an account before you have read and understood this Statement.

 

8. Rights of the data subject

The data subject has the right to access, rectify and erase personal data, and the right to restrict its processing, to data portability, and to object to processing. He/she may exercise the rights by contacting the members of the HESTIA consortium Personal Data Protection Officer: hestia-coordination@eurtd.com.

In case of doubt as to the identity of the person concerned, proof of identity may be requested.

If the members of the HESTIA consortium fail to respond or if its response is unsatisfactory, the data subject may also lodge a complaint with a supervisory authority for the protection of personal data.

For France, go to the site: https://www.cnil.fr/en/home.

 

9. Modification of the personal data protection information statement

The members of the HESTIA consortium may change this Statement in order to remain compliant with the practices adopted and with the regulation relating to the protection of personal data. The data subject will be informed of substantial changes.