1. General and principle-based commitment
STERIGENE is committed to processing all collected data in compliance with the applicable data protection legislation (Law No. 78-17 of 6 January 1978 as amended, and the European General Regulation 2016/679 of 27 April 2016 on data protection, these two texts being hereinafter referred to as the "Regulations").
This general data protection policy is addressed to:
- Recipients of STERIGENE's services
- Professional partners of STERIGENE
- Individual clients or prospects of STERIGENE
- STERIGENE employees
- Candidates wishing to join STERIGENE
- Internet users browsing the STERIGENE website
2. Definitions and terminology under the Regulations
- Processing of personal data is an operation or organised set of operations carried out on personal data (collection, structuring, storage, modification, communication…).
- Personal data is information that enables a human being (natural person) to be identified, directly (for example their name/first name) or indirectly (for example their telephone number, contract number or acronym).
- The data subject is the person who can be identified by the data used in the context of personal data processing.
- The data controller is the party who decides how personal data processing will be implemented, in particular by determining what the data will be used for and what tools will be used to process it.
- The processor is the party who carries out operations on the data on behalf of the data controller. They sign a contract with the data controller, who entrusts them with certain tasks and ensures that they have the technical and organisational safeguards enabling them to process the personal data entrusted to them in accordance with the regulations.
- The recipient is the party who receives authorised communication of personal data.
3. STERIGENE's commitment as data controller
STERIGENE is the controller of the processing carried out in the context of its business activities and, in this capacity, makes the following commitments:
- Personal data is used solely for explicit, legitimate and specified purposes linked to its various business activities, as stated each time at the point of collection of said data, in accordance with Article 29 of the European Regulation.
- We do not communicate or transfer personal data to third parties, but only to authorised recipients strictly within the framework of the defined purposes.
- We entrust personal data to subcontractor service providers selected on the basis of appropriate technical and organisational safeguards, in order to guarantee the protection of the data entrusted to them under the instructions of STERIGENE.
- Data subjects are informed in advance and on a regular basis, in a clear and transparent manner, in particular regarding the purpose of use of their data, the optional or mandatory nature of their responses in forms, the rights they hold in terms of data protection and the means of effectively exercising those rights, and the recipients.
- Whenever required by the Regulations, explicit, informed, active and unambiguous consent of the data subject is obtained in relation to the processing of their personal data.
- In order to ensure the protection of the personal data collected, appropriate security measures are implemented by STERIGENE, its support services and its contractually engaged subcontractors.
- STERIGENE and its subcontractors are committed to monitoring any possible and exceptional data breach and to taking all protective and corrective measures following a breach, notifying the CNIL within the required timeframes and, where applicable, the data subjects concerned.
At STERIGENE, all employees and contributors are, or are in the process of being, made aware of the data protection principles contained in the regulations, through regular information tailored to their activity and responsibilities.
Employees have access only to the information necessary for their activity. Sensitive data is subject to specific authorisations and controls.
4. Data Protection Officer
Given the size of the company, STERIGENE has not deemed it necessary to appoint a Data Protection Officer. A steering committee oversees compliance with the Regulations and the rules described in this Privacy and Data Protection Policy.
The steering committee oversees in particular:
- The establishment and updating of a record of personal data processing activities carried out within the company
- Ensuring that practices comply with the regulations and their developments
- Raising awareness among all STERIGENE teams of the requirements and best practices in terms of personal data protection
- The effective exercise of the rights of data subjects
The steering committee dedicated to data protection can be reached at the following contact details:
– By email: sterigene@sterigene.com
– By post:
Comité de pilotage RGPD
STERIGENE
2 RUE ANDRE CITROEN
95130 FRANCONVILLE
5. Purpose of use of the data you entrust to us
STERIGENE uses personal data for the following main purposes:
- Managing its client portfolio and prospect ranges
- Providing online services to professionals (B2B), via services accessible from the website of their service providers or within the framework of mobile applications
- Human resources management and recruitment
- Managing external professional contacts, including informing professionals and the general public
- Statistical analysis of its activities
- Commercial prospecting of professionals and other individuals, subject to their consent
- Implementing continuing professional training programmes
The above processing operations are necessary for the performance of a contract between a data subject and STERIGENE, or to pursue a legitimate interest such as fulfilling a legal obligation or informing professional contacts about STERIGENE's activities, or in certain cases are based on the explicit consent of the data subject.
6. Recipients of the data you entrust to us
On a case-by-case basis for the processing operations described in the "Use of data" article above, STERIGENE determines the recipients of the data based on their roles and their authorisations to receive data in compliance with the defined purposes. As a principle, only those who need to know personal data as part of their function have access to the data.
7. Personal data retention period
Data is not retained beyond the period necessary for the operations for which it was collected, taking into account the nature of the operations and the requirements of the law and legal provisions.
STERIGENE has established rules regarding the retention period of personal data of data subjects, in order to limit retention to a strictly necessary duration. By way of example, the following cases can be cited:
- Personal data collected from parties involved in the implementation of projects and contracts: retained for the duration of the project and contract, then archived for a minimum of 10 years
- Personal data collected from employees in the context of their career within the company: legal administrative period provided for by law
At the end of the period thus defined, and depending on the case, personal data is subject — in compliance with applicable Regulations — to one of the following measures:
- Deletion
- Archiving
8. Security measures implemented to protect the data entrusted to us
Data security concerns the measures taken to protect data from the following:
- Destruction, loss, alteration, unauthorised disclosure of personal data transmitted, stored or processed, or unauthorised access to such data, whether accidental or unlawful.
In order to guarantee the security of personal data, STERIGENE and its subcontractors implement appropriate technical and organisational measures, taking into account the state of knowledge, costs, the nature, scope, context and purposes of the processing, in order to guarantee a level of security appropriate to the risks.
In particular, and where necessary, the following measures have been taken:
- Encryption of personal data
- Deployment of means to guarantee the confidentiality and integrity of data
9. Your rights over the data communicated
Each data subject has the following rights:
- To access their data (right of access): the data subject may directly ask STERIGENE whether it holds information about them, and request that a list of the data be communicated to them.
- To request rectification (right of rectification): the data subject may request the rectification of inaccurate information concerning them. The right of rectification complements the right of access.
- To request erasure of their data (right to be forgotten): the data subject may request the erasure of information concerning them, for a reason provided for by the Regulations.
- To request restriction of processing of their data (right to restriction): the data subject may obtain restriction of the processing of their data, for a reason provided for by the Regulations.
- To request portability of their data (right to portability): the data subject may request to receive the data they have provided to STERIGENE, or request that STERIGENE transfer it to another data controller, for a reason provided for by the Regulations.
- To define advance directives regarding the fate of their data after their death.
The data subject may also object, on legitimate grounds, to their data being processed, disseminated, transmitted, retained or hosted.
For more information on the meaning of these rights, the CNIL has created a dedicated section for understanding your rights: https://www.cnil.fr/fr/comprendre-vos-droits
To exercise their rights, the data subject may contact STERIGENE:
– By email: sterigene@sterigene.com
– By post:
Comité de Pilotage RGPD
STERIGENE
2 RUE ANDRE CITROEN
95130 FRANCONVILLE
To facilitate the process and in particular to accelerate the processing time, STERIGENE invites each data subject, when submitting a request to exercise their rights, to:
- Indicate which right(s) they wish to exercise
- Clearly state their name / first name / contact details to which they wish to receive responses
- Attach a copy of a piece of identity document
10. Complaint to the CNIL
Each data subject has the right to lodge a complaint with a data protection supervisory authority.
In France, this authority is the CNIL, whose contact details are as follows:
– Website: https://www.cnil.fr/
– Telephone: 01 53 73 22 22
– Postal address:
CNIL
3 Place de Fontenoy
TSA 80715
75334 PARIS CEDEX 07
STERIGENE participates in and complies with all the Specifications and Policies of the IAB Europe Transparency & Consent Framework. It uses Consent Management Platform No. 92.