Article 1: Preamble
- How their personal data is collected and processed. Personal data shall be considered to be all data that is likely to identify a user. This includes the first and last name, age, postal address, e-mail address, location of the user or his IP address;
- What are the rights of the users concerning these data;
- Who is responsible for processing the personal data collected and processed;
- To whom this data is transmitted;
- Possibly, the site’s policy on “cookies”.
Registration policy and certification policies
Article 2: General principles on data collection and processing
In accordance with the provisions of Article 5 of the European Regulation 2016/679, the collection and processing of data of the users of the site respect the following principles:
- Lawfulness, fairness and transparency: data may only be collected and processed with the consent of the user who owns the data. Whenever personal data is collected, the user will be informed that his or her data is being collected and for what purpose the data is being collected;
- Minimisation of data collection and processing: only the data necessary for the proper execution of the purposes pursued by the site are collected;
- Conservation of data reduced in time: the data is kept for a limited period, of which the user is informed. When this information cannot be communicated, the user is informed of the criteria used to determine the period of retention;
- Integrity and confidentiality of collected and processed data: the data controller undertakes to guarantee the integrity and confidentiality of the data collected.
In order to be lawful, and in accordance with the requirements of Article 6 of the European Regulation 2016/679, the collection and processing of personal data may only take place if they comply with at least one of the following conditions:
- The user has expressly consented to the processing;
- The processing is necessary for the proper performance of a contract;
- The processing meets a legal obligation;
- The processing is necessary for the protection of the vital interests of the data subject or of another natural person;
- Processing may be necessary for the performance of a task carried out in the public interest or in the exercise of official authority;
- The processing and collection of personal data is necessary for the purposes of the legitimate and private interests pursued by the controller or by a third party.
Article 3: Personal data collected and processed in the context of navigation on the site
A. Data collected and processed and method of collection
The personal data collected on the netheos.com website are the following:
- Email address ;
- Name and first name ;
- Telephone number.
This data is collected when the user carries out one of the following operations on the site:
- Request for a demonstration ;
- Newsletter subscription.
The data controller will keep all the data collected in its computer systems on the site under reasonable security conditions for a period of : 13 months.
The collection and processing of data is for the following purposes:
Responding to requests sent through forms.
The data processing carried out is based on the following legal bases:
Consent of the user.
B. Transmission of data to third parties
The personal data collected by the website are not passed on to any third party and are only processed by the website publisher.
C. Data hosting
The netheos.com website is hosted by : OVEA, whose headquarters are located at the following address:
59 rue Nelson Mandela, 34070 Montpellier
The host can be contacted on the following telephone number: +33 4 67 67 00 00.
The data collected and processed by the site are exclusively hosted and processed in France.
Article 4: Data controller and Data Protection Officer
A. The data controller
The person responsible for the processing of personal data is: the Netheos DPO. He can be contacted as follows:
By email: firstname.lastname@example.org
The data controller is responsible for determining the purposes and means of processing personal data.
B. Obligations of the data controller
The data controller undertakes to protect the personal data collected, not to transmit them to third parties without the user’s knowledge and to respect the purposes for which the data were collected.
The site has an SSL certificate to guarantee that the information and data transfer through the site are secure.
The purpose of an SSL certificate (“Secure Socket Layer” Certificate) is to secure the data exchanged between the user and the site.
In addition, the data controller undertakes to notify the user in the event of rectification or deletion of the data, unless this would entail disproportionate formalities, costs and steps for the user.
In the event that the integrity, confidentiality or security of the user’s personal data is compromised, the data controller undertakes to inform the user by any means.
C. The Data Protection Officer
Furthermore, the user is informed that a Data Protection Officer has been appointed: For the attention of the Netheos DPO.
The role of the Data Protection Officer is to ensure the proper implementation of national and supranational provisions relating to the collection and processing of personal data. He or she may also be appointed as DPO (for Data Protection Officer).
The Data Protection Officer can be reached as follows:
By email: email@example.com
Article 5: Rights of the user
In accordance with the regulations concerning the processing of personal data, the user has the following rights.
In order for the data controller to comply with the request, the user is required to provide the data controller with his first and last name and e-mail address.
The data controller is obliged to respond to the user within a maximum of 30 (thirty) days.
A. Presentation of the user's rights regarding data collection and processing
a. Right of access, rectification and deletion
The user may view, update, modify or request the deletion of his or her personal data in accordance with the procedure set out below:
The user must send an e-mail to the person responsible for processing personal data, specifying the purpose of the request via the form: Access to your data
b. Right to data portability
The user has the right to request the portability of his/her personal data, held by the site, to another site, by complying with the following procedure:
The user must make a request for the portability of his/her personal data to the data controller via the form Access to your data
c. Right to limit and object to data processing
The user has the right to request the limitation of or to object to the processing of his/her data by the site, without the site being able to refuse, unless it can be shown that there are legitimate and compelling reasons, which may override the interests and rights and freedoms of the user.
In order to request the limitation of the processing of his/her data or to formulate an opposition to the processing of his/her data, the user must follow the following procedure:
The user must make a request to limit the processing of his/her personal data via the form Access to your data
d. Right not to be subject to a decision based exclusively on an automated process
In accordance with the provisions of Regulation 2016/679, the user has the right not to be subject to a decision based exclusively on an automated process if the decision produces legal effects concerning him/her, or significantly affects him/her in a similar way.
e. Right to determine the fate of data after death
The user is reminded that he/she can organise what should happen to his/her collected and processed data if he/she dies, in accordance with the law n°2016-1321 of 7 October 2016.
f. Right to refer to the competent supervisory authority
In the event that the data controller decides not to respond to the user’s request, and the user wishes to contest this decision, or, if he/she believes that one of the rights listed above has been infringed, he/she is entitled to refer the matter to the CNIL (Commission Nationale de l’Informatique et des Libertés, https://www.cnil.fr) or any competent judge.
B. Personal data of minors
In accordance with the provisions of Article 8 of the European Regulation 2016/679 and the French Data Protection Act, only minors aged 15 or over may consent to the processing of their personal data.
If the user is a minor under the age of 15, the consent of a legal representative will be required in order for personal data to be collected and processed.
The site editor reserves the right to verify by any means that the user is over 15 years of age, or that he/she has obtained the consent of a legal representative before browsing the site.
The site editor reserves the right to modify it in order to ensure that it complies with the law in force.