GDPR

DATA PROTECTION POLICY
Last updated: February 2023

WHY ADOPT A DATA PROTECTION POLICY?

The company HENAULT L’immobilière de Ré – Rivedoux Plage (or «the company») attaches great importance to the protection of your data and makes every effort to protect it.

HENAULT Real Estate in Ré – Rivedoux Plage operates with complete transparency and in accordance with applicable regulations, in particular the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data(hereinafter «GDPR») and to the Law No. 78-17 of 6 January 1978 relating to information technology, data files and civil liberties.

This Privacy Policy (hereinafter also referred to as "this Policy") applies to the processing of personal data carried out by the company within the framework of its customer relationship. The company is in no way responsible for the collection and processing of data by the client with its end customers.

In the case of "Cloud software" (or "SAAS") solutions, the company is a subcontractor within the meaning of the GDPR for the client and must apply the necessary measures to maintain the security, confidentiality, integrity and availability of the data that the client entrusts to it through the "Cloud software".

We reserve the right to modify this Policy at any time, particularly to reflect any regulatory, legislative, or jurisprudential changes, or changes to our services. Whenever possible, we will inform you of any substantial modifications to this Policy by any means. We encourage you to review this Policy regularly to stay informed about how we process your data.

WHO IS AFFECTED BY THE PROCESSING OF PERSONAL DATA?

The persons concerned (hereinafter also referred to as "you") by the processing carried out by the company are all persons whose personal data is processed within the framework of the contractualization of the software solution.

The personal data of "end customers" may be subject to automatic processing such as sending emails, but only after managing consent by the customer.

Access to end-customer personal data is only done with the customer's consent and solely for maintenance purposes and by duly authorized personnel.

INFORMATION ABOUT OUR PROCESSING OF YOUR DATA

WHO IS THE DATA CONTROLLER?

The data controller is HENAULT L'immobilière de Ré – Rivedoux Plage, a company under French law, with a share capital of 3712 euros, registered with the Trade and Companies Register under number 429962574, VAT number FR 67429962574 and whose registered office is located at 2 avenue d'Antioche 17670 LA COUARDE SUR MER (article 4.7 GDPR).

APPOINTMENT OF AN EXTERNAL DATA PROTECTION OFFICER (HEREINAFTER "DPO")

The DPO of HENAULT L’immobilière de Ré – Rivedoux Plage is M Isabelle HENAULT, who can be contacted by email at isabellehenault@henaultimmo.com.

WHAT CATEGORIES OF DATA DO WE PROCESS AND WHY?

Below, we detail the personal data we process according to the purposes we pursue, as well as how we collect it. We only process the following data when it is relevant and strictly necessary for the processing.

Operations related to managing our relationships with our prospects

Legal basis

Article 6.1.b): Implementation of pre-contractual measures
Art. 6.1.f): Legitimate interest of the company

Purposes

  • We provide demonstrations of tools and solutions to our prospective clients upon request.
  • Managing relationships with prospects who have expressed an interest in the tools and solutions.
  • Providing advice, information or answers to questions of any kind from prospective clients.

This purpose is based on the company's legitimate interest in processing the personal data of prospective customers who contact it in order to be able to respond to their requests/questions.

Source and categories of data processed

We can contact you via our forms, by phone or by email:

  • Personal identification data (name, surname, telephone number, email address);
  • Professional data (agency, company and professional address);
  • Any other information that you may have provided to us.

Operations related to managing our relationships with our clients

Legal basis

Article 6.1.b): performance of the contract

Purposes

Customer service is available on request by phone, email and any other means of communication following your request.

Source and categories of data processed

We can contact you via our forms, by phone or by email:

  • Personal identification data (name, surname, telephone number, email address);
  • Professional data (agency, company and professional address);
  • Any other information that you may have provided to us.

Operations related to managing our relationships with our (potential) partners

Legal basis

Article 6.1.b): execution of pre-contractual or contractual measures

Purposes

  • Managing the procedures for selecting our potential partners.
  • Managing our agreements with our partners.
  • Implementation of joint projects.

Source and categories of data processed

Contacting you by email:

  • Personal identification data (email);
  • Professional data (agency);
  • Any other information that you may have provided to us.

General email management

Legal basis

Art. 6.1.f): Legitimate interest

Purposes

  • Managing received messages.

The company has a legitimate interest in processing the data of individuals who contact it in order to be able to respond appropriately.

Source and categories of data processed

Beside you:

  • Personal identification data (name, surname, email);
  • Any other data that you may have provided to us.

Other operations related to software usage

Legal basis

Art. 6.1.a): consent
Art. 6.1.f): Legitimate interest of the company

Purposes

  • We improve our services by analyzing website usage. This analysis allows us to enhance the relevance and user-friendliness of our services.
  • Ensuring the safety and proper functioning of the site

The company has a legitimate interest in ensuring information security and the proper functioning of its software solution.

Source and categories of data processed

Beside you:

  • Electronic identification data collected by our cookies (IP address, connection logs, location, connection date and time and other metadata).

Operations related to requests to exercise rights, disputes and litigation

Legal basis

Art. 6.1.c): compliance with a legal obligation
Art. 6.1.f): Legitimate interest of the company

Purposes

  • Management of requests to exercise rights received electronically or by post.

In order to safeguard and defend the interests of the company, we have a legitimate interest in processing your data in the context of any dispute or litigation that may oppose us to you.

Source and categories of data processed

With you or with a third party:

  • Personal identification data (name, surname, email, copy of identity card);
  • Any other information relating to your request;
  • Within the framework of purpose 24: any other information arising from the dispute or litigation surrounding it.

We do not use automated decision-making techniques that produce legal effects concerning the data subject or significantly affect them.

HOW LONG DO WE KEEP YOUR DATA?

Your personal data is kept only for as long as necessary to fulfill the purpose for which we hold it. We ensure that retention periods are relevant and comply with legal requirements.

Regarding specific data retention periods, we have defined the following periods:

The time required for processing:

  • Data or images collected under a contract, which are kept for the period fixed in the framework that binds us to you;
  • Messages received in the general email inbox are, in principle, kept for the time necessary to reply to them. They are then deleted.

 

The retention periods for your data collected via cookies are detailed in our #Policy regarding cookie#.

At the end of the retention periods mentioned above, personal data will be deleted or we will proceed to anonymize it.

WHO RECEIVES YOUR DATA?

As part of providing our services, we may sometimes share your data. Under all circumstances, we ensure a high level of data protection.

Internal recipients of the data controller

We only grant access to your personal data to internal personnel whose role requires it. We regularly monitor this access and secure the information shared, to the extent possible.

External recipients of the data controller

Subcontractors, joint controller and separate controller

In accordance with Article 28 of the GDPR, our subcontractors' access to your data is based on signed contracts that specify their obligations regarding the protection of data security and confidentiality.

As part of our activities, we may sometimes share your data with the following recipients:

  • Cloud file storage and sharing service providers;
  • Customer and prospect relationship management (CRM) tool;
  • Service providers performing part of the software maintenance

Third party

Within the limits of their responsibilities, various actors in the justice system and public authorities, such as courts and tribunals, administrative authorities, and legal representatives, may have access to personal data only upon legal request.

SECURITY MEASURES IN PLACE TO PROTECT YOUR DATA

As the data controller, we take all necessary precautions to ensure the security and confidentiality of your data. This includes the physical security of the buildings housing our systems and the security of our IT systems to prevent external access to your data. Access to your data is limited to those individuals who have a genuine need to know.

WHAT ARE YOUR RIGHTS REGARDING YOUR PERSONAL DATA?

In accordance with Articles 15 to 22 of the GDPR, any natural person using the service has the right to exercise the following rights:

HOW CAN YOU EXERCISE YOUR RIGHTS?

CONTACT US?

If you have a suggestion or question about how we process your data or about our Policy, please do not hesitate to contact us!

Our contact details are available on the website's legal notice page.

DO YOU WISH TO FILE A COMPLAINT WITH A SUPERVISORY AUTHORITY?

If you believe that your rights have not been respected, you can also file a complaint with the National Commission for Information Technology and Civil Liberties (hereinafter the "CNIL"), whose contact details are as follows:

  • On the CNIL website via the online complaint service;
  • By Postal Mail:
    • CNIL
      Complaints Department
      3 Place de Fontenoy
      TSA 8071
      75334 Paris Cedex 07

You also always have the option of filing a legal appeal.