DATA PROTECTION POLICY
Last updated: February 2023
The company HENAULT L’immobilière de Ré – Rivedoux Plage (or «the company») attaches great importance to the protection of your data and makes every effort to protect it.
HENAULT Real Estate in Ré – Rivedoux Plage operates with complete transparency and in accordance with applicable regulations, in particular the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data(hereinafter «GDPR») and to the Law No. 78-17 of 6 January 1978 relating to information technology, data files and civil liberties.
This Privacy Policy (hereinafter also referred to as "this Policy") applies to the processing of personal data carried out by the company within the framework of its customer relationship. The company is in no way responsible for the collection and processing of data by the client with its end customers.
In the case of "Cloud software" (or "SAAS") solutions, the company is a subcontractor within the meaning of the GDPR for the client and must apply the necessary measures to maintain the security, confidentiality, integrity and availability of the data that the client entrusts to it through the "Cloud software".
We reserve the right to modify this Policy at any time, particularly to reflect any regulatory, legislative, or jurisprudential changes, or changes to our services. Whenever possible, we will inform you of any substantial modifications to this Policy by any means. We encourage you to review this Policy regularly to stay informed about how we process your data.
The persons concerned (hereinafter also referred to as "you") by the processing carried out by the company are all persons whose personal data is processed within the framework of the contractualization of the software solution.
The personal data of "end customers" may be subject to automatic processing such as sending emails, but only after managing consent by the customer.
Access to end-customer personal data is only done with the customer's consent and solely for maintenance purposes and by duly authorized personnel.
WHO IS THE DATA CONTROLLER?
The data controller is HENAULT L'immobilière de Ré – Rivedoux Plage, a company under French law, with a share capital of 3712 euros, registered with the Trade and Companies Register under number 429962574, VAT number FR 67429962574 and whose registered office is located at 2 avenue d'Antioche 17670 LA COUARDE SUR MER (article 4.7 GDPR).
APPOINTMENT OF AN EXTERNAL DATA PROTECTION OFFICER (HEREINAFTER "DPO")
The DPO of HENAULT L’immobilière de Ré – Rivedoux Plage is M Isabelle HENAULT, who can be contacted by email at isabellehenault@henaultimmo.com.
Below, we detail the personal data we process according to the purposes we pursue, as well as how we collect it. We only process the following data when it is relevant and strictly necessary for the processing.
Operations related to managing our relationships with our prospects
Article 6.1.b): Implementation of pre-contractual measures
Art. 6.1.f): Legitimate interest of the company
This purpose is based on the company's legitimate interest in processing the personal data of prospective customers who contact it in order to be able to respond to their requests/questions.
We can contact you via our forms, by phone or by email:
Operations related to managing our relationships with our clients
Article 6.1.b): performance of the contract
Customer service is available on request by phone, email and any other means of communication following your request.
We can contact you via our forms, by phone or by email:
Operations related to managing our relationships with our (potential) partners
Article 6.1.b): execution of pre-contractual or contractual measures
Contacting you by email:
General email management
Art. 6.1.f): Legitimate interest
The company has a legitimate interest in processing the data of individuals who contact it in order to be able to respond appropriately.
Beside you:
Other operations related to software usage
Art. 6.1.a): consent
Art. 6.1.f): Legitimate interest of the company
The company has a legitimate interest in ensuring information security and the proper functioning of its software solution.
Beside you:
Operations related to requests to exercise rights, disputes and litigation
Art. 6.1.c): compliance with a legal obligation
Art. 6.1.f): Legitimate interest of the company
In order to safeguard and defend the interests of the company, we have a legitimate interest in processing your data in the context of any dispute or litigation that may oppose us to you.
With you or with a third party:
We do not use automated decision-making techniques that produce legal effects concerning the data subject or significantly affect them.
Your personal data is kept only for as long as necessary to fulfill the purpose for which we hold it. We ensure that retention periods are relevant and comply with legal requirements.
Regarding specific data retention periods, we have defined the following periods:
The time required for processing:
The retention periods for your data collected via cookies are detailed in our #Policy regarding cookie#.
At the end of the retention periods mentioned above, personal data will be deleted or we will proceed to anonymize it.
As part of providing our services, we may sometimes share your data. Under all circumstances, we ensure a high level of data protection.
Internal recipients of the data controller
We only grant access to your personal data to internal personnel whose role requires it. We regularly monitor this access and secure the information shared, to the extent possible.
External recipients of the data controller
Subcontractors, joint controller and separate controller
In accordance with Article 28 of the GDPR, our subcontractors' access to your data is based on signed contracts that specify their obligations regarding the protection of data security and confidentiality.
As part of our activities, we may sometimes share your data with the following recipients:
Third party
Within the limits of their responsibilities, various actors in the justice system and public authorities, such as courts and tribunals, administrative authorities, and legal representatives, may have access to personal data only upon legal request.
As the data controller, we take all necessary precautions to ensure the security and confidentiality of your data. This includes the physical security of the buildings housing our systems and the security of our IT systems to prevent external access to your data. Access to your data is limited to those individuals who have a genuine need to know.
In accordance with Articles 15 to 22 of the GDPR, any natural person using the service has the right to exercise the following rights:
If you have a suggestion or question about how we process your data or about our Policy, please do not hesitate to contact us!
Our contact details are available on the website's legal notice page.
If you believe that your rights have not been respected, you can also file a complaint with the National Commission for Information Technology and Civil Liberties (hereinafter the "CNIL"), whose contact details are as follows:
You also always have the option of filing a legal appeal.