1. General commitment and principles
SYNEXIN is committed to processing all collected data in compliance with applicable data protection legislation (Law No. 78-17 of 6 January 1978 as amended, and the European General Data Protection Regulation 2016/679 of 27 April 2016, hereinafter collectively referred to as the "Regulations").
This general data protection policy applies to:
- Beneficiaries of SYNEXIN's services
- Professional partners of SYNEXIN
- Individual clients or prospects of SYNEXIN
- SYNEXIN employees
- Candidates wishing to join SYNEXIN
- Internet users browsing the SYNEXIN website
2. Definitions and terminology under the Regulations
- Processing of personal data refers to any operation or organised set of operations carried out on personal data (collection, structuring, storage, modification, communication, etc.).
- Personal data is any information that enables an individual (natural person) to be identified, either directly (e.g. their name) or indirectly (e.g. their telephone number, contract number or acronym).
- The data subject is the individual who can be identified by the data used in the context of personal data processing.
- The data controller is the party that determines the manner in which personal data processing is to be implemented, in particular by determining the purposes for which the data will be used and the tools to be employed to process it.
- The data processor is the party that carries out operations on data on behalf of the data controller. It enters into a contract with the data controller, which assigns it certain tasks and ensures that it has the technical and organisational safeguards in place to process the personal data entrusted to it in accordance with the Regulations.
- The recipient is the party that receives authorised communication of personal data.
3. SYNEXIN's commitment as data controller
SYNEXIN is the controller of the processing carried out in the context of its business activities and, in this capacity, makes the following commitments:
- Personal data is used solely for explicit, legitimate and specified purposes related to its various activities, as indicated at the time of collection of said data, in accordance with Article 29 of the European Regulation.
- We do not communicate or transfer personal data to third parties, but only to authorised recipients within the strict scope of the defined purposes.
- We entrust personal data to subcontractors selected on the basis of appropriate technical and organisational safeguards, in order to ensure the protection of the data entrusted to them under the instructions of SYNEXIN.
- Data subjects are informed in advance and on a regular basis, in a clear and transparent manner, in particular regarding the purpose of use of their data, whether their responses in forms are optional or mandatory, the rights available to them in terms of data protection and the means of effectively exercising those rights, and the recipients of their data.
- Wherever required by the Regulations, an explicit, informed, active and unambiguous consent from the data subject is obtained for the processing of their personal data.
- In order to ensure the protection of collected personal data, appropriate security measures are implemented by SYNEXIN, its support services and its contractually engaged subcontractors.
- SYNEXIN and its subcontractors are committed to monitoring any potential and exceptional data breach and to taking all protective and corrective measures following a breach, notifying the CNIL within the required timeframes and, where applicable, the data subjects concerned.
At SYNEXIN, all employees and contributors are, or are in the process of being, made aware of the principles of data protection as set out in the Regulations, through regular information sessions tailored to their activities and responsibilities.
Employees have access only to the information necessary for their role. Sensitive data is subject to specific authorisations and controls.
4. Data Protection Officer
Given the size of the company, SYNEXIN has not deemed it necessary to appoint a Data Protection Officer. A steering committee oversees compliance with the Regulations and the rules described in this Privacy and Data Protection Policy.
The steering committee is responsible in particular for:
- Establishing and maintaining a register of personal data processing activities carried out within the company
- Ensuring that practices comply with the Regulations and their developments
- Raising awareness among all SYNEXIN teams of the requirements and best practices regarding personal data protection
- Ensuring the effective exercise of data subjects' rights
The steering committee dedicated to data protection can be reached at the following contact details:
— By email: synexin@synexin.fr
— By post:
Comité de pilotage RGPD
SYNEXIN
2 RUE ANDRE CITROEN
95130 FRANCONVILLE
5. Purposes of use of the data you entrust to us
SYNEXIN uses personal data for the following primary purposes:
- Managing its client portfolio and prospect lists
- Providing online services to professionals (B2B), via services accessible from their service providers' websites or through mobile applications
- Managing human resources and recruitment
- Managing external professional contacts, including communication with professionals and the general public
- Statistical analysis of its activities
- Commercial prospecting of professionals and other individuals, subject to their consent
- Delivering continuing professional development training programmes
The above processing activities are necessary for the performance of a contract entered into between a data subject and SYNEXIN, or in pursuit of a legitimate interest such as compliance with a legal obligation or the provision of information to professional contacts regarding SYNEXIN's activities, or in certain cases are based on the data subject's explicit consent.
6. Recipients of the data you entrust to us
On a case-by-case basis, for the processing activities described in the "Data use" article above, SYNEXIN determines the recipients of data based on their roles and their authorisation to receive data, in compliance with the defined purposes. As a general principle, only those individuals who need to access personal data in the context of their role are granted access to such data.
7. Personal data retention periods
Data is not retained beyond the period necessary for the purposes for which it was collected, taking into account the nature of the operations and the requirements of applicable law and legal obligations.
SYNEXIN has established rules regarding the retention periods for the personal data of data subjects, in order to limit retention to the strictly necessary duration. By way of example:
- Personal data collected from parties involved in the execution of projects and contracts: retained for the duration of the project and contract, then archived for a minimum of 10 years
- Personal data collected from employees in the context of their career within the company: retained in accordance with the statutory administrative retention periods prescribed by law
At the end of the defined retention period, and depending on the circumstances, personal data is subject to one of the following measures, in compliance with applicable Regulations:
- Deletion
- Archiving
8. Security measures implemented to protect entrusted data
Data security encompasses the measures taken to protect data from the following:
- Destruction, loss, alteration, unauthorised disclosure of personal data transmitted, stored or processed, and unauthorised access to such data, whether accidental or unlawful.
In order to ensure the security of personal data, SYNEXIN and its subcontractors implement appropriate technical and organisational measures, taking into account the state of the art, costs, the nature, scope, context and purposes of processing, in order to ensure a level of security appropriate to the risks.
In particular, and wherever necessary, the following measures have been implemented:
- Encryption of personal data
- Deployment of means to ensure the confidentiality and integrity of data
9. Your rights regarding the data provided
Each data subject has the following rights:
- Right of access: the data subject may directly ask SYNEXIN whether it holds information about them and request to be provided with the list of data held.
- Right of rectification: the data subject may request the correction of inaccurate information concerning them. The right of rectification complements the right of access.
- Right to erasure (right to be forgotten): the data subject may request the deletion of information concerning them, on grounds provided for by the Regulations.
- Right to restriction of processing: the data subject may obtain restriction of the processing of their data, on grounds provided for by the Regulations.
- Right to data portability: the data subject may request to receive the data they have provided to SYNEXIN, or request that SYNEXIN transmit it to another data controller, on grounds provided for by the Regulations.
- Right to define advance directives regarding the fate of their data after their death.
The data subject may also object, on legitimate grounds, to the processing, dissemination, transmission, storage or hosting of data concerning them.
For further information on the meaning of these rights, the CNIL has created a dedicated section: https://www.cnil.fr/fr/comprendre-vos-droits
To exercise these rights, the data subject may contact SYNEXIN:
— By email: synexin@synexin.fr
— By post:
Comité de Pilotage RGPD
SYNEXIN
2 RUE ANDRE CITROEN
95130 FRANCONVILLE
To facilitate the process and in particular to expedite processing times, SYNEXIN invites each data subject, when submitting a request to exercise their rights, to:
- Indicate which right(s) they wish to exercise
- Clearly state their full name and contact details to which they wish to receive responses
- Attach a copy of a valid identity document
10. Complaints to the CNIL
Each data subject has the right to lodge a complaint with a data protection supervisory authority.
In France, this authority is the CNIL, whose contact details are as follows:
— Website: https://www.cnil.fr/
– Telephone : 01 53 73 22 22
– Postal address :
CNIL
3 Place de Fontenoy
TSA 80715
75334 PARIS CEDEX 07
SYNEXIN participates in and complies with all Specifications and Policies of the IAB Europe Transparency & Consent Framework. It uses Consent Management Platform No. 92.