Privacy Policy
INTRODUCTION
This policy outlines the undertakings and measures implemented by the Alter Solutions Group in the processing of data transmitted or collected to ensure ongoing compliance with the texts applicable to data protection by the European General Data Protection Regulation 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data, and applicable local data protection laws in the countries where we operate, these texts being hereinafter referred to as the "Regulation").
The purpose of this Policy is to provide clear information on the way in which your personal data is collected and used by the Alter Solutions Group.
DEFINITIONS
Processing of personal data: means any organised set of operations carried out on personal data (collection, structuring, storage, modification, communication, etc.).
Personal data: means any information relating to an identified or identifiable natural person (hereinafter referred to as "data subject"); an "identifiable natural person" is one who can be identified, directly or indirectly, in particular by reference to an identifier, such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Sensitive data: means all data relating to racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, as well as genetic data, biometric data, data concerning the health of a natural person or data concerning sex orientation are all classified as sensitive data.
Processing of sensitive data is strictly prohibited, except in circumstances where:
- The data subject concerned has given explicit consent;
- The processing forms a necessary part of the execution of the contract with the data subject.
Data subject: means any identifiable natural person who can be identified through the processing of personal data.
Data controller: means the natural or legal person who determines how the processing of personal data shall be undertaken, including the purposes the data will be used for as well as the means of processing to be used.
Subcontractor: any natural person who carries out data processing operations on behalf of the Data controller. By virtue of their agreement with the Data controller they are entrusted with certain tasks and required to provide technical and organisational guarantees relating to their capacity to process the personal data entrusted to them in compliance with the prevailing regulations.
Recipient: means any natural person who receives an authorised communication of personal data.
Cookie: refers to a set of data or collection of data stored on a computer (personal computer or other device connected to the Internet) necessary for the operation of a particular website.
Personal data breach: means a security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
WHO ARE WE?
The Alter Solutions Group is a technology consulting group that provides services and expertise to support our customers in the implementation of their technical projects dedicated to software engineering and cybersecurity.
Our ambition is guided by three strategic development axes:
- Increase our market position as technical experts;
- Expand our business to include international markets;
- Develop our employer brand in order to attract the best people.
SCOPE
This general data protection policy applies to the following categories:
- Professionals, partners within the group
- Employees of the group
- Prospective applicants wishing to join the group
- Natural persons who are clients or prospects of the group
- Internet users browsing alter-solutions.com
- All computer and telecommunication resources (in whatever form, tangible or intangible) necessary for the creation, processing, exchange and storage of personal data.
NATURE OF THE DATA
In accordance with the data minimisation principle, only personal data that is strictly necessary shall be collected and processed.
The information that may be collected includes the following:
- The marital status of the Data Subject:
- Last name / Maiden name
- First names
- Nationality
- Civil status data (Gender, First and Last name of spouse, Family members, etc.)
- Address, postal code and town of residence
- Personal and business telephone number(s)
- Personal and professional e-mail(s)
- The professional life of the Data Subject:
- Position, Grade, Salary
- Working hours: clock in and out times
- Photographs, videos
- Addresses, site plans and technical data relating to buildings or installations (subject to intellectual property and contractual rights)
- The connection data of the Data Subject:
- IP address of the terminal or equipment connected to the Internet
- Data specific to the technical equipment used to access the services provided by the companies within the group (PC, smartphone, web browser, etc.)
- Personal Data that collected from publicly available databases and/or on social network
- Cookies
- Browser history
LIST OF DOCUMENTS
The documents listed below contain personal data collected or transmitted in the form of PDF attachments:
- Identity documents (ID cards, passports, residence permits, etc.)
- Electrical accreditations, driving licenses, CACES (Certificate of Aptitude in Safe Driving)
- Medical appointments
- Data provided as part of the Curriculum Vitae, and contained in the attached letters
- Diplomas, educational qualifications
- Proof of address
- Photographic identification
- Bank statement
- Recognition of disabled worker status, disability card
- Partial/Permanent Disability
PURPOSE OF THE PROCESSING
DEPARTMENT CONCERNED |
PROCESSING |
PURPOSE |
PROCUREMENT |
Processing and administration relating to suppliers/service providers |
|
ACCOUNTING / TAXATION |
Management of principal and subsidiary accounts and invoicing |
|
COMMUNICATIONS |
Internal communication activities |
|
External communication activities |
|
|
Management of copyright and permissions relating to images |
|
|
ISD |
IT asset management |
|
Management of data hosting |
|
|
Management of computer directories and definition of IS access rights |
|
|
Administration of Guest WiFi |
|
|
LEGAL |
Administration of all legal affairs on behalf of the company |
|
Administration of delegated authority and signatories within the company |
|
|
Administration of contractual relations with corporate partners |
|
|
Management of unpaid invoices |
|
|
Management of GDPR requests from Data Subjects |
Monitoring and management of individual requests made in connection with the exercise of their GDPR rights:
|
|
GENERAL SERVICES
|
Video surveillance |
|
Management of fixed lines and mobile telephones |
|
|
MARKETING / PROSPECTING |
Direct marketing operations |
|
Operation of the website |
|
|
HUMAN RESOURCES |
Management of recruitment operations |
|
Direct contact with potential candidates |
|
|
Offer of employment |
|
|
Administrative management of personnel |
|
|
Management of leave, work stoppages / accidents, working time |
|
|
Management of internal directories and organisational charts |
|
|
Career and mobility management |
|
|
Expense reports |
|
|
Payroll management |
|
|
Management of the employee savings scheme |
|
|
Other benefits |
Benefits may change according to office location and policy |
RETENTION PERIOD
Data shall be kept in a form that allows the identification of the Data Subjects for no longer than is necessary for the purposes for which they are processed or for any obligation mentioned in GDPR articles.
The retention period shall be defined in a way that is appropriate, precise and proportional to the purpose of each processing operation.
ACCOUNTABILITY OF THE DIFFERENT STAKEHOLDERS
The data processors shall only collect and process the personal data that is voluntarily transmitted to them, or provided by the various software or hardware resources (ERP, Time & Attendance, Internet routers, etc.).
The Alter Solutions Group has put in place an organisation that relies on the skills and accountability of those involved in all operations related to the processing of personal data. We raise awareness and take steps to implement dedicated data protection training to increase everyone's awareness and knowledge of the subject.
TRANSPARENCY
In accordance with the above, and unless it is necessary to communicate personal data to companies whose intervention as third party service providers on behalf and under the control of the responsible party is required for the aforementioned purposes, the Group shall not pass on any personal data collected nor sell, license or otherwise exchange the data with any organisation or entity, unless the corresponding data subjects have been duly informed thereof in advance and have provided their explicit consent, unless required by law, for example in the context of legal proceedings.
When subcontracting, we take all reasonable steps to ensure that the subcontractors provide sufficient guarantees regarding the protection of personal data; we ensure that appropriate technical and organisational measures have been implemented in order to guarantee the protection of personal data and the rights of the Data Subject.
We structure the relationship with the subcontractor through contractual GDPR liability clauses as part of the proper execution of the terms of the contract.
LIMITING DATA TRANSFER TO A THIRD COUNTRY
ALTERSOLUTIONS strives to keep the Personal Data in France, or at least within the European Economic Area (EEA).
However, it is possible that the Data we collect when you use our platform or services may be transferred to other countries. This is for example the case if some of our service providers are located outside the European Economic Area.
In the event of such a transfer, we guarantee that it will be carried out:
- To a country ensuring an adequate level of protection, i.e. a level of protection equivalent to what the European Regulations require.
- Within the framework of standard contractual clauses.
- Within the framework of internal company rules.
COOKIES
For more information about cookies, their categorisation and detail, please refer to our Cookie Policy.
SAFETY
Alter Solutions Group is committed to protecting the Personal Data we collect, or that we process, from loss, destruction, alteration, unauthorized access, or disclosure.
PERSONAL DATA BREACHES
In the event of a personal data breach relating to processing operations that represents a high risk to data subjects and falls within the scope of a privacy impact assessment, the Alter Solutions Group undertakes to:
- Notify the supervisory authority within a period of no more than 72 hours from the discovery of the breach;
- Identify and inform those affected by the breach, as appropriate.
PRIVACY RIGHTS
Alter Solutions Group shall ensure that data subjects have the ability to exercise their rights in connection with their personal data.
Right to information
the right to have clear, precise, and complete information on the use of Personal Data by Alter Solutions Group.
Right of access
This right is intended to ensure that the Data Subject has access to all data and details of the processing that concerns them in order to determine the information held by Alter Solutions Group or to verify the accuracy of the same.
Right to rectification
This right allows a Data Subject to request the correction of any inaccurate, obsolete and/or incomplete personal data.
Right to erasure / right to be forgotten
This right allows a Data Subject to request the erasure or deletion of personal data held by Alter Solutions Group, unless Alter Solutions Group has a legitimate interest in keeping it.
Right to restriction of processing
This right allows a Data Subject, under certain conditions, to request that Alter Solutions Group restrict the processing of personal data processed by the company.
Right to data portability
This right allows a Data Subject to retrieve personal data in order to store or transmit said data from one information system to another.
Right to object
This right allows a Data Subject to object to the processing of any personal data for reasons related to the particular situation of the Data Subject (under conditions).
Right to withdraw consent
The right at any time to withdraw consent where processing is based on consent.
Right not to be subject to an automated processing decision
The Data Subject shall have the right not to be subject to a decision which may include a measure involving the assessment of certain personal aspects relating to them which is taken solely on the basis of automated processing and which produces legal effects concerning them or which similarly significantly affects them, including profiling.
Right to define post-mortem directives
The right for the applicant to define directives concerning the fate of Personal Data after his/her death.
The above rights can be exercised at any time:
- Sending an e-mail to the following address: privacy@alter-solutions.com
- Or by writing to: ALTER SOLUTIONS - Data Protection Officer (DPO) – 6 Avenue du Général de Gaulle – 78 000 Versailles - FRANCE
-
You also have the right to file a complaint with the competent Data Protection Authority (DPA) of any member state of the European Union. For a complete list of these authorities and their direct contacts, please access this website: https://edpb.europa.eu/about-edpb/about-edpb/members_en
-
Regarding any processing of data undertaken to ensure appropriate monitoring of the risks of money laundering and terrorist financing, pursuant to Article L.561-45 of the French Monetary and Financial Code, your requests for access to these files should be addressed to the Commission Nationale Informatique et Libertés – 3 place de Fontenoy, 75007 Paris.
-
Regarding direct marketing communications, you may choose at any time not to receive them by using the unsubscribe link directly accessible from the message.