Personal data privacy policy
Onepoint, a company incorporated under French law, registered with the Paris Trade Register under number 440 697 712 and domiciled at 29 rue des Sablons, 75116 Paris in France (“onepoint”, “we”, “our”) respects the privacy of any person providing personal data.
Aware of the importance of ensuring the confidentiality of personal data, onepoint undertakes, within the framework of its activities and in accordance with the legislation in force in France and in Europe (Regulation 2016/679 of the European Parliament and the Council of 27 April 2016), to ensure the protection, confidentiality and security of personal data, as well as the respect for privacy.
This external Privacy Policy (“Privacy Policy”) describes how onepoint, its subcontractors and potential partners collect and process the personal data of its clients, suppliers, website visitors, visitors to its premises, applicants, partners and more generally any person whose data it may possess, in accordance with the General Personal Data Protection Regulation (“GDPR”).
It also describes the legal basis applicable to personal data processing, the people we share such data with, and the way in which it is stored.
Onepoint is the Data Controller. This means that we decide how we retain and use your personal data. Under the GDPR, we are required to provide you with all information contained in the Privacy Policy.
It is important that you read this Privacy Policy, as well as any other information that we may provide on specific occasions when we collect or process your personal data, so that you know how and why we use such data.
1 – How is your personal data collected?
The data we collect or hold about you may come from a variety of sources. Some of it has been collected directly from you, or from your company; some may have been collected in compliance with applicable regulations in the past. Also under applicable regulations, we may also collect information about you when you interact with us, for example when you visit our websites (https://www.groupeonepoint.com/en/) or when you use our mobile applications, when you call us, when you visit our premises or attend events we organise (meetups, conferences, meetings, etc.), when you participate in contests we organise, or when you use certain social media (twitter, facebook , linkedin, etc.). Some data may come from sources accessible to the public (for example from the press and websites or applications of all kinds including social media) or from external companies.2 – Type of personal data, purposes and legal basis
By personal data, we refer to any information about a person from which that person can be identified. This does not include data for which the identity has been deleted (anonymous data). Below you will find an overview of the different types of data subjects covered by this Privacy Policy as well as:- Type of personal data about you that we use and store;
- Purposes for which this personal data is collected;
- Legal basis for data processing
- Retain the required data in order to comply with legal requirements;
- Manage data communication requests from competent authorities
2.1 – Type of data subjects: site users/visitors
Type of personal data- Surname, first name
- E-mail address
- IP address
- Connection data (cookies)
- Any information you may have included in the contact form
2.2. Type of data subjects: applicants for a position in europe
Type of personal data- Full name
- Telephone number
- E-Mail address
- City, Country
- Any information you may have included on your CV
2.3. Type of data subjectfs: customers / prospective customers
Type of personal data- Full name
- Telephone number
- Business e-mail address
- Business postal address
- Title
- Hierarchy
- Company name
- Reports and record of actions
- Bank details
2.4. Type of data subjects: suppliers
Type of personal data- Last name, birth name
- Date of birth
- Country of birth
- Telephone number
- Business e-mail address
- Business postal address
- Title
- Reports and record of actions
- Company name
- SIREN number
- Bank details
2.5. Type of data subjects: visitors to onepoint premises
- Type of personal data
- Full name
- Business e-mail address
- Company name
- Title
- CCTV footage
- Recording of images such as photographs, video footage and live video streaming
3. If you fail to provide personal data
If you choose not to supply the personal data we request, we may not be able to provide you with the products and/or services you have requested or achieve the purposes for which we have requested such personal data.4. What are personal data flows?
4.1. How do we share your data?
We may share your personal data with companies within the onepoint Group. We share your personal data with third parties when required by law, when necessary to manage our contractual relationship with you or when we have any other legitimate interest in doing so. We may need to disclose personal data in response to a request from a regulatory authority, such as the tax authorities or CNIL (the French data protection authority), etc., and/or a court (in response to a judgement, a court order or injunction) upon request or if the law requires us to do so, in order to protect our interests, our property and/or our security and/or those of a third party. We may also share personal data with companies assisting in the fight against fraud and investigating fraud. We may also disclose your personal data as part of the fight against money laundering and terrorist financing, with the implementation of monitoring of contracts and/or transactions which could lead to the drawing up of a suspicious activity report or the freezing of assets. We may transfer your personal data to service providers not affiliated with the onepoint Group, such as:- Banks and insurance companies;
- Providers of computer systems and support for our business, including providers of delivery services, email archiving, backup and disaster recovery service providers, and providers of cybersecurity, hosting and maintenance services;
- Marketing and advertising service providers.
- If we sell or buy a business or assets, we may disclose your personal data to the seller or prospective purchaser of this business or these assets;
- In the event that onepoint or almost all of its assets are acquired by a third party, in which case the personal data held by onepoint will be part of the transferred assets;
4.1.1. External providers
As part of our business, especially those regarding recruitment, eLearning and communication, we employ the services of service providers not affiliated with the onepoint Group. Thus, you may be required to communicate on a voluntary basis, some of your personal data directly on their platform, for example, through subscription to a newsletter or the creation of a personal user account. For these treatments, the providers act as the Data Controller. For more information, we invite you to read their own privacy policy.4.1.2. Recruitments efforts
Workday, recruitment platform: https://www.workday.com/en-us/privacy.html .4.1.3. Online training
360Learning, eLearning platform: https://360learning.com/privacy-policy .4.1.4. Communications / marketing
HubSpot, communication and marketing platform: https://legal.hubspot.com/privacy-policy . Contentsquare, develops and provides customer experience analytics services: https://contentsquare.com/fr-fr/privacy-center/privacy-policy4.1.5. Event management
Eventbrite, event management platform: https://www.eventbrite.com/support/articles/en_US/Troubleshooting/eventbrite-privacy-policy?lg=en_US.4.1.6. Customer relationship management
Salesforce, CRM plateform : https://www.salesforce.com/eu/company/privacy/. Survey Monkey, survey platform : https://www.surveymonkey.com/mp/legal/privacy-basics/.5. Data processing outside the European union
Onepoint does not transfer personal data outside the EEA, to countries that have not been the subject of an adequacy decision by the European Commission within the meaning of article 45 of the GDPR, or without standard contractual clauses of the European Commission having been concluded.6. Cookies
The term cookie covers all trackers that provide access to information stored in the terminal equipment of a visitor (web beacons, pixels, etc.). Thanks to cookies, we can collect your connection data (e.g. IP address, geographical position, type and version of your internet browser, operating system, information on your visits and use of our website, etc.). This helps us improve your browsing experience and site features. For more information on cookies, please refer to our cookies policy, accessible at the following address: www.groupeonepoint.com/en/cookie-policy.7. Personal data retention period
We will only retain your personal data for the time necessary to achieve the purposes for which we collected it, including to comply with any legal or accounting requirement. To determine the appropriate retention period for personal data, we take into account the quantity, nature and sensitivity of personal data, the potential risk of harm resulting from the unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and the possibility of attaining those purposes by other means, as well as the applicable legal requirements. Processing and retention period Site user and visitor data- Claims, questions, complaints: 3 years following the closure of a claim, question or complaint.
- Cookies: for more information on cookies, please refer to our cookies policy, accessible at the following address: www.groupeonepoint.com/en/cookie-policy.
- During the term of the contractual relationship with onepoint, plus another 3 years without prejudice to the retention obligations or limitation periods.
- We store your information for a maximum of 3 years from the last contact.
- We store your information for a period of time relevant to the purpose for which we process it, and for a maximum of 3 years from the end of our business relationship.
- Non-selected applicants: in the event of a negative outcome to an application, we will inform you if we wish to retain your recruitment file, in order to give you the opportunity to request its destruction. If you do not request the destruction of your file, we will automatically delete your file 2 years after our last contact with you.
- Selected applicants: in the event of a positive outcome to an application, the onepoint staff privacy policy applies.
- We store your information for a maximum of 3 years from your last visit.
- We store your information for a maximum of one month from the date of recording.
- We store your information for a period of time relevant to the purpose for which we process it, and for a maximum of 3 years from the end of our business relationship.