Personal Data Protection Policy

A question? A need?

Our philosophy and commitments

Direction RH is committed to protecting your personal data and ensures a high level of protection of your personal data in accordance with European Regulation 2016/679 and the French Data Protection Act No. 78-17.

In this regard, you will find below our personal data protection policy explaining in particular what we collect as personal data, how it is processed and on what basis, its retention and your personal rights. We invite you to read it.

Our Data Protection Officer is available to answer all your questions; you can contact them at the following address: rgpd@directionrh.fr

You can find the text of the applicable European Regulation here → https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX%3A32016R0679 or query/contact the regulatory authority (CNIL) via its website www.CNIL.fr.

The current version of the personal data policy may be modified by us if necessary and you will be informed accordingly.

Your data controller

Direction RH is the data controller of your personal data and whose contact details you will find below: 2 allée des bouleaux 77123 NOISY SUR ECOLE; it is referred to by its name or “We” in these terms.

Your personal data and its collection by Direction RH

Your personal data may be collected during:

  • Your visit to our website
  • Our exchanges
  • Our prospecting activities
  • The training or execution of our contracts

We do not collect any data that is unnecessary for the processing purpose mentioned at the time of collection or data prohibited by law or regulations.

The collection of certain data may be mandatory or optional and you are informed of the mandatory information. Your personal data may be collected by third-party service providers or partners, who are committed to complying with European and national regulations on personal data.

Our policy is not to transfer your data outside the European Union; if by exception we do so, this transfer can only take place to a country or organisation subject to an adequacy decision (art.45 GDPR) or presenting appropriate sufficient guarantees (art.46 GDPR).

We do not make any automated decisions.

We may potentially collect the following personal data:

  • Civil status, identity, contact details, images
  • Professional life
  • Personal data of an economic and financial nature, connection data
  • Internet & telephony

Our processing of your personal data

We process your personal data by entering it into databases; it is stored, retained and where applicable rectified, deleted, archived, anonymised or pseudonymised, transferred to trusted third parties.

We are led to process your personal data for the following processing purposes or for purposes specified to you at the time of collection:

1. Your information on our commercial offers (products, services…) and promotional offers

Communicating with you
We may use your personal data for commercial prospecting purposes, and in particular to send you information about our products/services, our commercial and promotional offers, quotes and other pre-contractual documents, our news by email, post or telephone.

2. The execution of your current contracts and customer follow-up
We use your personal data to ensure the execution of current contracts in accordance with your requests. We may also send you all information about your order or current contracts, their execution, your invoices and contractual documents, advice, the execution of our guarantees where applicable and our legal obligations. We also use your personal data to manage our customer relationship, your requests or complaints, disputes where applicable and to monitor your customer history.

3. Improving the use of our services and improving our offers
We process your personal data to allow you optimal use of our services, improve our offers and products/services, and to monitor your user journey, carry out satisfaction surveys, anonymous polls and statistics.

4. Your payments
Your bank details may be collected either directly by us or by a dedicated and selected service provider, who guarantees the complete confidentiality of your bank details and these details are only retained for the time necessary for the duration of the contractual relationship or within legal limits.

5. Protection against fraudulent initiatives
The personal data collected may be used to combat fraud, particularly on payments or direct debits made. In this regard, our payment security service providers may receive this data.

6. Ensuring compliance with the law and court decisions
Your data may be used to:

  • Respond to a request from an administrative or judicial authority, a representative of the law, an auxiliary of justice or to comply with a court decision
  • Ensure compliance with our general terms and conditions of sale/service
  • Protect our rights and/or obtain compensation for damages we may suffer or limit their consequences
  • Prevent any action contrary to current laws, particularly in the context of fraud risk prevention

We may also be led to process your personal data for the following purposes:

Miscellaneous

  • Dissemination of administrative and scientific information
  • Agenda management
  • Execution of legal or contractual guarantees

Cookie management

  • Necessary cookies — for optimised use of the site (e.g. identification, basket)
  • Performance cookies — (enabling anonymous statistics and traffic levels on the site) and monitoring and personalisation collecting information on your use of the site and enabling individualisation of our offers
  • Third-party cookies — to target advertisements likely to interest you based on your detected areas of interest (these cookies are subject for their issue and processing to the policy applied by third parties and not to Direction RH’s policy)
  • Analytical cookies — enabling us to understand and analyse your navigation on our site

The legal basis for processing your personal data

In accordance with regulations, the processing of your personal data by us is lawful if it is based on one of the following bases:

  • Your consent to the processing of your data by us: you accept the processing of your personal data through express consent. You can withdraw this consent at any time from our DPO; or
  • The existence of a contract between you and us: the processing of data is then justified by the needs of the execution of the contract; or
  • Our legitimate interest in processing your personal data provided that this proportionate interest respects your fundamental rights and your private life; or
  • The Law or current regulations when these oblige us to process and retain your personal data.

Methods and retention periods for your personal data

We manage your personal data according to three phases:

  • An active phase where data is retained for the time indicated below in the “active” database: your personal data is then only accessible by persons with an operational need to access it in order to carry out authorised processing
  • An archiving phase (for an additional period to retention in the “active” database) when a legitimate reason justifies it: your personal data is then archived with restricted access and for a limited period
  • A deletion or anonymisation phase: at the end of the additional archiving within the periods below, your personal data is deleted or anonymised (so that it can no longer constitute personal data identifying you)

Your personal data is retained for the time necessary for the purposes of their processing, our customer relationship where applicable and the execution of contracts and within the specifically enacted regulatory limits; we may retain your personal data in archiving for the purposes of retaining accounting, tax or probative supporting documents for the duration of applicable limitation periods. As an example, we indicate below the retention periods applicable to the following processing (subject to regulations imposing a different retention period):

Processing purpose

Legal basis

Retention of personal data in the “active” database

Additional archiving

Prospecting Your consent 3 years if you have not actively responded to any solicitation. The period restarts upon active solicitation on your part.  X
Execution of our contractual obligations to you / services  Contract The time necessary for the execution of the contract and 3 years from the end of the commercial relationship (last activity such as end of contract execution (purchase, service…), connection to the site as a registered user) 5 years after the end of the contractual relationship
Customer relationship Contract 3 years from the end of the commercial relationship (last activity on your part with us) 5 years after the end of the contractual relationship
Recruitment Pre-contractual measures The time necessary for the completion of the recruitment process X
Newsletter management Your consent Until your unsubscription X

Withdrawal of your consent to the collection or processing of your personal data

Your consent given for the collection of your personal data may be withdrawn by writing to our DPO by email or by post to the addresses appearing in the header, mentioning your name, first name, email and address with the precise nature and subject of your withdrawal request.

You may also send any comments on your personal data to Direction RH 2 allée des bouleaux 77123 NOISY SUR ECOLE.

    Exercising your rights over your personal data

    You have:

    • A right of access, which allows you to obtain:Confirmation that data concerning you is or is not being processed
    • Communication of a copy of all personal data held by the data controller
    • A right to request portability of certain data: it allows you to retrieve your personal data in a structured, commonly used and machine-readable format.
    • A right of objection: it allows you to no longer be subject to commercial prospecting from us or our partners, or, for reasons relating to your particular situation, to have the processing of your data for research and development, fraud prevention and prevention purposes ceased.
    • A right of rectification: it allows you to have information concerning you corrected when it is obsolete or incorrect. It also allows you to have incomplete information concerning you completed.
    • A right of erasure: it allows you to obtain the erasure of your personal data subject to legal retention periods. It may in particular apply in cases where your data would no longer be necessary for processing.
    • A right of restriction: it allows you to limit the processing of your data in the following cases:

    – In cases of unlawful use of your data
    – If you contest the accuracy of your data
    – If it is necessary to retain the data to establish, exercise or defend your rights

    They will then no longer be subject to active processing, and may not be modified for the duration of the exercise of this right.

    • A right to obtain human intervention: data controllers may use automated decision-making for the purpose of subscribing to or managing your contract. In this case, you may ask what were the determining criteria for the decision from the Data Protection Officer.

    You may exercise these rights by electronic mail: rgpd@directionrh.fr or by letter to the following address: 2 allée des bouleaux 77123 NOISY SUR ECOLE indicating your name, first name, address and email (where applicable your customer references) as well as the subject of your request in clear and legible terms. Direction RH undertakes to follow up on your verified request within one month of receipt.

    In case of difficulty, you may address yourself directly to our personal data protection officer directly by email: rgpd@directionrh.fr or contact the Commission Nationale de l’Informatique et des Libertés (CNIL).

    Our subcontractors and partners

    Direction RH may transfer your personal data to subcontractors carrying out services involving the processing of your data and in compliance with the purposes referred to herein; these subcontractors must afford your personal data the same level of confidentiality as Direction RH and have committed to being in full compliance with personal data regulations, including the GDPR.

    We do not trade your personal data; if you wish to know more and specifically find out the identity of the service providers or partners to whom your personal data has been transferred, you may contact our DPO at the following address: rgpd@directionrh.fr

    The service providers or partners likely to access your personal data may in particular be:

    • Service providers likely to manage outsourced services for the execution of our services and contracts
    • Service providers helping us improve our services, carry out data analysis and optimise our offers, conduct surveys and statistics
    • Statutory auditors, chartered accountants, consultants, lawyers, audit firms, IT and managed services providers, security providers
      Investors and acquirers

    We may also be led to transfer your personal data to French authorities, administrations and courts particularly in the context of legal action or legal formalities requiring such communication.