politique de confidentialité
Mentions légales
Les explications et informations fournies sur cette page sont d'ordre général et visent à vous guider dans la rédaction de votre propre politique de confidentialité. Cet article ne saurait constituer un avis juridique ni une recommandation quant aux mesures à prendre, car nous ne pouvons connaître à l'avance les politiques de confidentialité spécifiques que vous souhaitez mettre en place entre votre entreprise et vos clients et visiteurs. Nous vous recommandons de consulter un avocat afin de mieux comprendre et de vous accompagner dans la création de votre politique de confidentialité.
Politique de confidentialité - Les bases
Cela étant dit, une politique de confidentialité est un document qui décrit en détail comment un site web collecte, utilise, divulgue, traite et gère les données de ses visiteurs et clients. Elle comprend généralement une déclaration concernant l'engagement du site web à protéger la vie privée de ses visiteurs et clients, ainsi qu'une explication des différents mécanismes mis en œuvre à cette fin.
Les obligations légales relatives au contenu d'une politique de confidentialité varient selon les juridictions. Il vous incombe de vous assurer que vous respectez la législation applicable à vos activités et à votre lieu d'implantation.
What to Include in the Privacy Policy
De manière générale, une politique de confidentialité aborde souvent les points suivants : les types d’informations collectées par le site web et la manière dont elles sont collectées ; une explication des raisons pour lesquelles le site web collecte ces types d’informations ; les pratiques du site web en matière de partage des informations avec des tiers ; les moyens dont disposent vos visiteurs et clients pour exercer leurs droits conformément à la législation applicable en matière de protection de la vie privée ; les pratiques spécifiques concernant la collecte de données des mineurs ; et bien plus encore.
Pour en savoir plus, consultez notre article « Créer une politique de confidentialité ».
10. Cookies and Similar Technologies
The Website may use cookies and similar technologies.
A cookie is a small file stored on or accessed from a user’s device when visiting a website.
10.1 Strictly necessary cookies
These cookies are essential for the operation of the Website. They may be used to:
-
maintain an active session;
-
store security settings;
-
save privacy preferences;
-
operate user accounts;
-
prevent fraud.
These cookies may not require user consent when they are strictly necessary to provide a service requested by the user.
10.2 Cookies requiring consent
With the user’s consent, APIMPEX may use cookies to:
-
measure audience and traffic;
-
analyse browsing behaviour;
-
personalise content;
-
display advertising;
-
measure campaign effectiveness;
-
integrate third-party services or content.
Users may accept, refuse, or customise cookies through the consent banner or cookie management tool.
Refusing non-essential cookies does not prevent access to the essential features of the Website.
Consent management tool used: [TO BE COMPLETED]
A detailed list of cookies, their providers, purposes, and retention periods must be available through the Website’s cookie management tool.
11. Analytics Tools and Third-Party Services
APIMPEX may use technical tools or services provided by third parties when they are necessary for the operation, security, communication, or improvement of the Website.
The following list must be adapted to reflect the services actually used:
-
website analytics tool: [TO BE COMPLETED];
-
customer relationship management tool: [TO BE COMPLETED];
-
email service provider: [TO BE COMPLETED];
-
payment service provider: [TO BE COMPLETED];
-
video conferencing tool: [TO BE COMPLETED];
-
mapping service: [TO BE COMPLETED];
-
embedded video services: [TO BE COMPLETED];
-
artificial intelligence provider: [TO BE COMPLETED];
-
error monitoring and security tool: [TO BE COMPLETED].
Non-essential services that may place cookies or access information stored on a user’s device will only be activated after consent has been obtained, where required.
12. Artificial Intelligence and Recommendations
When APIMPEX uses artificial intelligence tools to assist users, improve product descriptions, classify categories, or provide recommendations, APIMPEX takes steps to:
-
limit transmitted data to what is necessary;
-
inform users about the relevant use of artificial intelligence;
-
avoid transmitting unnecessary sensitive or confidential data;
-
contractually regulate service providers;
-
protect the confidentiality of commercial information.
Unless otherwise stated, automated recommendations do not produce legal effects or similarly significant effects for users.
Where a fully automated decision produces such effects, APIMPEX will provide specific information about how it works, its consequences, and the rights available to the individual concerned.
13. Transfers Outside the European Union
Some service providers may be located or operate servers outside the European Union or European Economic Area.
In such cases, APIMPEX ensures that the transfer is based on a mechanism recognised by applicable data protection regulations, including:
-
an adequacy decision issued by the European Commission;
-
Standard Contractual Clauses approved by the European Commission;
-
Binding Corporate Rules;
-
any other appropriate safeguard permitted under the GDPR.
Additional security measures may be implemented where necessary.
Individuals may contact APIMPEX to obtain information about the safeguards applicable to international transfers.
14. Data Retention Periods
APIMPEX retains personal data only for as long as necessary for the purpose for which it was collected, subject to applicable legal obligations.
As a general guideline:
-
account data: for the duration of the account, followed by the period required to manage possible complaints or legal claims;
-
contractual and business relationship data: for the duration of the business relationship, followed generally by five years;
-
invoices and accounting records: ten years in accordance with accounting obligations;
-
prospect data used for marketing purposes: three years from collection or the last contact initiated by the prospect;
-
customer data used for marketing purposes: for the duration of the business relationship and for three years after it ends;
-
customer service requests: for the period necessary to handle the request, followed by the applicable limitation period;
-
data relating to the exercise of individual rights: for the period required to process the request and retain evidence of its handling;
-
technical logs and security data: for a period proportionate to security requirements;
-
cookies: for the period indicated in the cookie management tool.
At the end of the applicable retention period, personal data is deleted, anonymised, or archived where continued retention is required to comply with a legal obligation or defend a legal claim.
15. Data Security
APIMPEX implements appropriate technical and organisational measures to protect personal data against:
-
unauthorised access;
-
loss;
-
destruction;
-
alteration;
-
disclosure;
-
fraudulent use;
-
any other form of unlawful processing.
These measures may include:
-
encryption of communications using HTTPS;
-
access rights management;
-
account protection;
-
data backups;
-
system monitoring;
-
software updates;
-
awareness training for authorised personnel;
-
contractual safeguards with processors.
As no transmission or storage method can guarantee absolute security, APIMPEX regularly adapts its security measures according to the risks identified.
16. Personal Data Breaches
In the event of a personal data breach that may create a risk to individuals’ rights and freedoms, APIMPEX will take the necessary measures to:
-
limit the consequences of the incident;
-
identify the affected data;
-
document the breach;
-
notify the French Data Protection Authority, the CNIL, where required;
-
inform affected individuals where the risk is considered high.
17. Individual Rights
In accordance with applicable data protection regulations, individuals may exercise the following rights, subject to the conditions provided by law:
-
right of access;
-
right to rectification;
-
right to erasure;
-
right to restriction of processing;
-
right to object;
-
right to data portability;
-
right to withdraw consent at any time;
-
right to issue instructions concerning the handling of personal data after death;
-
right not to be subject to a fully automated decision producing legal or similarly significant effects, where applicable.
Right to object to direct marketing
Individuals may object at any time and without providing a reason to the use of their personal data for direct marketing purposes.
After an objection is received, APIMPEX may retain the information strictly necessary on an objection list to prevent further marketing communications.
18. Exercising Your Rights
Requests may be submitted:
By email: [PRIVACY EMAIL ADDRESS TO BE COMPLETED]
By post:
APIMPEX – Personal Data Protection
60 Rue François Ier
75008 Paris
France
The request should specify:
-
the right the individual wishes to exercise;
-
the information required to locate the relevant account or personal data;
-
the address to which the response should be sent.
Proof of identity may only be requested where necessary to verify the requester’s identity, particularly where there is reasonable doubt.
APIMPEX will respond within the time limits required by law. This period may be extended where a request is complex or where multiple requests have been received, provided that the individual is informed of the extension.
19. Complaints to the CNIL
Individuals who believe that their data protection rights have not been respected may submit a complaint to the Commission Nationale de l’Informatique et des Libertés – CNIL, the French Data Protection Authority.
However, individuals are encouraged to contact APIMPEX first so that the request or concern can be reviewed and addressed.
20. Children’s Data
APIMPEX services are primarily intended for professionals and adults who have the legal capacity required to use the services.
APIMPEX does not knowingly seek to collect personal data relating to children.
Where such collection is brought to its attention and there is no valid legal basis for retaining the data, APIMPEX may delete the information concerned.
21. Links to Third-Party Websites
The Website may contain links to websites, platforms, or services operated by third parties.
APIMPEX does not control the processing carried out by those third parties. Users are encouraged to read the relevant privacy policies before providing personal data.
22. Changes to this Privacy Policy
APIMPEX may amend this Privacy Policy to reflect:
-
legal or regulatory developments;
-
recommendations issued by supervisory authorities;
-
changes to its services;
-
the addition or removal of service providers;
-
changes to its personal data processing activities.
