politique de confidentialité
Mentions légales
Les explications et informations fournies sur cette page sont d'ordre général et visent à vous guider dans la rédaction de votre propre politique de confidentialité. Cet article ne saurait constituer un avis juridique ni une recommandation quant aux mesures à prendre, car nous ne pouvons connaître à l'avance les politiques de confidentialité spécifiques que vous souhaitez mettre en place entre votre entreprise et vos clients et visiteurs. Nous vous recommandons de consulter un avocat afin de mieux comprendre et de vous accompagner dans la création de votre politique de confidentialité.
Politique de confidentialité - Les bases
Cela étant dit, une politique de confidentialité est un document qui décrit en détail comment un site web collecte, utilise, divulgue, traite et gère les données de ses visiteurs et clients. Elle comprend généralement une déclaration concernant l'engagement du site web à protéger la vie privée de ses visiteurs et clients, ainsi qu'une explication des différents mécanismes mis en œuvre à cette fin.
Les obligations légales relatives au contenu d'une politique de confidentialité varient selon les juridictions. Il vous incombe de vous assurer que vous respectez la législation applicable à vos activités et à votre lieu d'implantation.
What to Include in the Privacy Policy
De manière générale, une politique de confidentialité aborde souvent les points suivants : les types d’informations collectées par le site web et la manière dont elles sont collectées ; une explication des raisons pour lesquelles le site web collecte ces types d’informations ; les pratiques du site web en matière de partage des informations avec des tiers ; les moyens dont disposent vos visiteurs et clients pour exercer leurs droits conformément à la législation applicable en matière de protection de la vie privée ; les pratiques spécifiques concernant la collecte de données des mineurs ; et bien plus encore.
Pour en savoir plus, consultez notre article « Créer une politique de confidentialité ».
3.7 Data collected from public sources
As part of its professional activities, APIMPEX may collect or verify information from:
-
public company registers;
-
professional websites;
-
professional directories;
-
chambers of commerce;
-
professional organisations;
-
legally accessible databases;
-
information voluntarily published by a company or its representative.
When data has not been collected directly from the individual concerned, APIMPEX will provide the required information in accordance with applicable regulations, unless a legal exception applies.
4. Purposes of Processing
Personal data may be used for the following purposes.
4.1 Website and account management
-
creating and administering accounts;
-
authenticating users;
-
securing access;
-
personalising services;
-
saving user preferences;
-
ensuring the technical operation of the platform.
4.2 Professional connections
-
publishing company profiles;
-
publishing products, services, and commercial requests;
-
connecting buyers, sellers, suppliers, and service providers;
-
transmitting quotation requests;
-
allowing users to communicate with each other;
-
providing relevant search results.
4.3 Transaction and contract management
-
preparing and processing orders;
-
managing quotations and contracts;
-
arranging payments;
-
managing invoicing;
-
monitoring deliveries;
-
handling complaints and disputes;
-
providing commercial or technical support.
4.4 Verification and security
-
verifying the identity or professional status of users;
-
combating fake profiles;
-
preventing fraud, abuse, attempted scams, or illegal use;
-
protecting users, APIMPEX, and its partners;
-
ensuring the security of the Website and information systems;
-
retaining evidence required to protect APIMPEX’s rights.
4.5 Communication and direct marketing
Subject to applicable rules, APIMPEX may use professional contact information to:
-
respond to enquiries;
-
present its services;
-
send news or commercial offers;
-
inform users about new features;
-
send newsletters;
-
conduct customer satisfaction surveys.
Recipients may unsubscribe at any time by using the unsubscribe link included in communications or by contacting APIMPEX.
4.6 Compliance with legal obligations
APIMPEX may process certain information to:
-
comply with accounting and tax obligations;
-
respond to requests from competent authorities;
-
comply with fraud prevention and anti-money laundering obligations;
-
comply with economic sanctions and trade regulations;
-
retain documents required by law;
-
establish, exercise, or defend legal claims.
5. Legal Bases for Processing
Depending on the purpose, processing carried out by APIMPEX is based on one or more of the following legal grounds.
Performance of a contract or pre-contractual measures
This legal basis applies in particular to:
-
account creation and management;
-
management of quotation requests;
-
professional connections;
-
order and transaction management;
-
payment and delivery management;
-
customer service.
Compliance with a legal obligation
This legal basis applies in particular to:
-
accounting and tax obligations;
-
retention of invoices;
-
legally valid requests from authorities;
-
compliance with regulatory obligations.
APIMPEX’s legitimate interests
APIMPEX may rely on its legitimate interests to:
-
secure the Website;
-
prevent fraud;
-
manage professional requests;
-
improve its services;
-
protect and defend its rights;
-
conduct certain business-to-business marketing activities, subject to the right to object.
Consent
Consent may be requested for:
-
sending certain marketing communications;
-
newsletter subscriptions;
-
placing non-essential cookies;
-
using certain analytics, advertising, or personalisation tools;
-
any other processing operation requiring prior consent.
Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.
6. Mandatory Information
Certain information is required to create an account, publish a profile, use a service, process a request, or complete a transaction.
Mandatory fields are identified in the relevant forms.
If required information is not provided, APIMPEX may be unable to:
-
create the account;
-
verify the user;
-
process the request;
-
provide the service;
-
enter into or perform the contract.
Other information is optional.
7. Recipients of Personal Data
Personal data is only accessible to individuals who require it to perform their duties.
It may be shared with:
-
authorised APIMPEX employees and contractors;
-
buyers, sellers, or service providers involved in a professional connection;
-
hosting and maintenance providers;
-
email and communication service providers;
-
payment service providers;
-
transport or logistics providers involved in a transaction;
-
customer relationship management providers;
-
authorised analytics and audience measurement providers;
-
legal advisers, accountants, and insurers;
-
government bodies, courts, and legally authorised authorities.
APIMPEX requires its processors to provide sufficient guarantees regarding confidentiality, security, and data protection.
APIMPEX does not sell users’ personal data to third parties.
8. Publication of Professional Profiles
The APIMPEX platform may allow professional users to publish information that is accessible to other users or to the public.
Depending on account settings, published information may include:
-
company name;
-
country;
-
business sector;
-
products and services;
-
company logo;
-
certifications;
-
name and position of a professional contact;
-
professional contact details;
-
purchase requests or sales offers.
Users must ensure that they have the necessary rights and authorisations before publishing information relating to another person.
APIMPEX may remove information that is clearly unlawful, fraudulent, misleading, or contrary to its Terms of Use.
9. Hosting and Technical Logs
The Website is hosted by:
Hosting provider: [HOSTING PROVIDER NAME TO BE COMPLETED]
Address: [HOSTING PROVIDER ADDRESS TO BE COMPLETED]
Hosting country: [COUNTRY TO BE COMPLETED]
The hosting provider may automatically collect technical server logs containing:
-
IP address;
-
browser information;
-
operating system;
-
page visited;
-
date and time of the request;
-
information relating to technical errors.
This information is used to ensure the security, availability, maintenance, and proper operation of the Website.
10. Cookies and Similar Technologies
The Website may use cookies and similar technologies.
A cookie is a small file stored on or accessed from a user’s device when visiting a website.
10.1 Strictly necessary cookies
These cookies are essential for the operation of the Website. They may be used to:
-
maintain an active session;
-
store security settings;
-
save privacy preferences;
-
operate user accounts;
-
prevent fraud.
These cookies may not require user consent when they are strictly necessary to provide a service requested by the user.
10.2 Cookies requiring consent
With the user’s consent, APIMPEX may use cookies to:
-
measure audience and traffic;
-
analyse browsing behaviour;
-
personalise content;
-
display advertising;
-
measure campaign effectiveness;
-
integrate third-party services or content.
Users may accept, refuse, or customise cookies through the consent banner or cookie management tool.
Refusing non-essential cookies does not prevent access to the essential features of the Website.
Consent management tool used: [TO BE COMPLETED]
A detailed list of cookies, their providers, purposes, and retention periods must be available through the Website’s cookie management tool.
11. Analytics Tools and Third-Party Services
APIMPEX may use technical tools or services provided by third parties when they are necessary for the operation, security, communication, or improvement of the Website.
The following list must be adapted to reflect the services actually used:
-
website analytics tool: [TO BE COMPLETED];
-
customer relationship management tool: [TO BE COMPLETED];
-
email service provider: [TO BE COMPLETED];
-
payment service provider: [TO BE COMPLETED];
-
video conferencing tool: [TO BE COMPLETED];
-
mapping service: [TO BE COMPLETED];
-
embedded video services: [TO BE COMPLETED];
-
artificial intelligence provider: [TO BE COMPLETED];
-
error monitoring and security tool: [TO BE COMPLETED].
Non-essential services that may place cookies or access information stored on a user’s device will only be activated after consent has been obtained, where required.
12. Artificial Intelligence and Recommendations
When APIMPEX uses artificial intelligence tools to assist users, improve product descriptions, classify categories, or provide recommendations, APIMPEX takes steps to:
-
limit transmitted data to what is necessary;
-
inform users about the relevant use of artificial intelligence;
-
avoid transmitting unnecessary sensitive or confidential data;
-
contractually regulate service providers;
-
protect the confidentiality of commercial information.
Unless otherwise stated, automated recommendations do not produce legal effects or similarly significant effects for users.
Where a fully automated decision produces such effects, APIMPEX will provide specific information about how it works, its consequences, and the rights available to the individual concerned.
13. Transfers Outside the European Union
Some service providers may be located or operate servers outside the European Union or European Economic Area.
In such cases, APIMPEX ensures that the transfer is based on a mechanism recognised by applicable data protection regulations, including:
-
an adequacy decision issued by the European Commission;
-
Standard Contractual Clauses approved by the European Commission;
-
Binding Corporate Rules;
-
any other appropriate safeguard permitted under the GDPR.
Additional security measures may be implemented where necessary.
Individuals may contact APIMPEX to obtain information about the safeguards applicable to international transfers.
14. Data Retention Periods
APIMPEX retains personal data only for as long as necessary for the purpose for which it was collected, subject to applicable legal obligations.
As a general guideline:
-
account data: for the duration of the account, followed by the period required to manage possible complaints or legal claims;
-
contractual and business relationship data: for the duration of the business relationship, followed generally by five years;
-
invoices and accounting records: ten years in accordance with accounting obligations;
-
prospect data used for marketing purposes: three years from collection or the last contact initiated by the prospect;
-
customer data used for marketing purposes: for the duration of the business relationship and for three years after it ends;
-
customer service requests: for the period necessary to handle the request, followed by the applicable limitation period;
-
data relating to the exercise of individual rights: for the period required to process the request and retain evidence of its handling;
-
technical logs and security data: for a period proportionate to security requirements;
-
cookies: for the period indicated in the cookie management tool.
At the end of the applicable retention period, personal data is deleted, anonymised, or archived where continued retention is required to comply with a legal obligation or defend a legal claim.
15. Data Security
APIMPEX implements appropriate technical and organisational measures to protect personal data against:
-
unauthorised access;
-
loss;
-
destruction;
-
alteration;
-
disclosure;
-
fraudulent use;
-
any other form of unlawful processing.
These measures may include:
-
encryption of communications using HTTPS;
-
access rights management;
-
account protection;
-
data backups;
-
system monitoring;
-
software updates;
-
awareness training for authorised personnel;
-
contractual safeguards with processors.
As no transmission or storage method can guarantee absolute security, APIMPEX regularly adapts its security measures according to the risks identified.
16. Personal Data Breaches
In the event of a personal data breach that may create a risk to individuals’ rights and freedoms, APIMPEX will take the necessary measures to:
-
limit the consequences of the incident;
-
identify the affected data;
-
document the breach;
-
notify the French Data Protection Authority, the CNIL, where required;
-
inform affected individuals where the risk is considered high.
17. Individual Rights
In accordance with applicable data protection regulations, individuals may exercise the following rights, subject to the conditions provided by law:
-
right of access;
-
right to rectification;
-
right to erasure;
-
right to restriction of processing;
-
right to object;
-
right to data portability;
-
right to withdraw consent at any time;
-
right to issue instructions concerning the handling of personal data after death;
-
right not to be subject to a fully automated decision producing legal or similarly significant effects, where applicable.
Right to object to direct marketing
Individuals may object at any time and without providing a reason to the use of their personal data for direct marketing purposes.
After an objection is received, APIMPEX may retain the information strictly necessary on an objection list to prevent further marketing communications.
18. Exercising Your Rights
Requests may be submitted:
By email: [PRIVACY EMAIL ADDRESS TO BE COMPLETED]
By post:
APIMPEX – Personal Data Protection
60 Rue François Ier
75008 Paris
France
The request should specify:
-
the right the individual wishes to exercise;
-
the information required to locate the relevant account or personal data;
-
the address to which the response should be sent.
Proof of identity may only be requested where necessary to verify the requester’s identity, particularly where there is reasonable doubt.
APIMPEX will respond within the time limits required by law. This period may be extended where a request is complex or where multiple requests have been received, provided that the individual is informed of the extension.
19. Complaints to the CNIL
Individuals who believe that their data protection rights have not been respected may submit a complaint to the Commission Nationale de l’Informatique et des Libertés – CNIL, the French Data Protection Authority.
However, individuals are encouraged to contact APIMPEX first so that the request or concern can be reviewed and addressed.
20. Children’s Data
APIMPEX services are primarily intended for professionals and adults who have the legal capacity required to use the services.
APIMPEX does not knowingly seek to collect personal data relating to children.
Where such collection is brought to its attention and there is no valid legal basis for retaining the data, APIMPEX may delete the information concerned.
21. Links to Third-Party Websites
The Website may contain links to websites, platforms, or services operated by third parties.
APIMPEX does not control the processing carried out by those third parties. Users are encouraged to read the relevant privacy policies before providing personal data.
22. Changes to this Privacy Policy
APIMPEX may amend this Privacy Policy to reflect:
-
legal or regulatory developments;
-
recommendations issued by supervisory authorities;
-
changes to its services;
-
the addition or removal of service providers;
-
changes to its personal data processing activities.