What is the purpose of our Privacy Policy?
Synneo, which manages this platform, places great importance on the protection and confidentiality of your personal data, which represent for us a guarantee of seriousness and trust.
As such, our Privacy Policy reflects our commitment to ensuring that Synneo complies with all applicable rules on personal data protection and, in particular, with the General Data Protection Regulation (“GDPR”).
Specifically, our Privacy Policy aims to inform you about how and why we process your personal data in connection with the services we provide to you.
Who is our Privacy Policy intended for?
Our Privacy Policy applies to you, regardless of your place of residence, as long as you are at least 15 years old and use our platform.
If you are under the legal age specified above, you are not permitted to use our services without the prior and explicit consent of one of your parents or a person holding parental authority. Such consent must be sent to us by email at dpo@synneo.fr.
If you believe that we hold personal data about your children without your consent, please contact us at the dedicated address indicated above.
Why do we process your personal data and on what legal basis?
We process your personal data primarily for the following purposes:
- To allow you to use and benefit from our service and all its features, based on our Terms of Use.
- To manage user accounts (e.g., account creation, access, deletion), based on our Terms of Use.
- To process online payments, based on our Terms of Sale.
- To send you essential technical emails (e.g., password changes, account notifications) necessary for the proper functioning of our service, based on our Terms of Use.
- To enable you to download and upload documents to our platform, based on our Terms of Use.
- To ensure and enhance the security and quality of our services (e.g., statistics, data protection) based on our legal obligations, our Terms of Use, and our legitimate interest in maintaining reliable services.
- To send our newsletter, based on our legitimate interest in customer loyalty and communication.
Your data is collected directly from you when you use our platform, and we are committed to processing it solely for the purposes described above.
What personal data do we process and for how long?
Below is a summary of the categories of personal data we process and their respective retention periods:
- Professional identification data (e.g., name, surname, position, company, etc.) and contact details (e.g., professional email address, phone number, etc.) are kept for the duration of the service provision plus applicable legal retention periods, generally 5 years.
- In cases where your business name matches your personal name (e.g., self-employed, small business), economic and financial data (e.g., bank account number, verification code, etc.) are retained for the duration necessary for the transaction and billing management, plus legal retention periods, generally 5 to 10 years.
- Email address for receiving technical messages is retained until your account is deleted.
- Email address for receiving our newsletter is retained until you unsubscribe from the newsletter.
- Connection data (e.g., logs, IP address, etc.) are retained for 1 year.
Once the applicable retention periods have expired, your personal data will be irreversibly deleted and can no longer be recovered. At most, we may retain anonymized data for statistical purposes.
Please note that in the event of a legal dispute, we are required to retain all data concerning you for the entire duration of the proceedings, even beyond the above-mentioned retention periods.
What rights do you have to control the use of your personal data?
Applicable data protection laws grant you specific rights that you may exercise at any time and free of charge to control how we use your data:
- Right of access and to obtain a copy of your personal data, provided this does not conflict with business secrecy, confidentiality, or correspondence privacy.
- Right to rectify personal data that are inaccurate, outdated, or incomplete.
- Right to request the erasure (“right to be forgotten”) of personal data that are not essential to the proper functioning of our services.
- Right to restrict processing of your personal data, allowing temporary suspension of data use in case of a dispute about processing legitimacy.
- Right to data portability, allowing you to retrieve part of your personal data to store or transfer them easily between systems.
- Right to give instructions regarding the handling of your data after your death, either directly or through a trusted third party or heir.
To ensure that your request is processed, it must be submitted directly by you or your authorized representative to dpo@synneo.fr. Requests sent by other means cannot be processed.
Requests must come directly from you or your authorized representative. We may request proof of identity if there is any doubt regarding the requester’s identity.
We will respond to your request as soon as possible and no later than three months from receipt, in cases where the request is technically complex or if we receive numerous requests at the same time.
Please note that we may refuse to process any request that is excessive or unfounded, particularly due to its repetitive nature.
Who can access your personal data?
Your personal data are processed by our teams, by our professional client for whom this platform is developed, and by our technical service providers solely for the purpose of operating our service.
We ensure that all our technical providers are carefully vetted before being engaged, to confirm their full compliance with applicable personal data protection rules.
FURTHERMORE, WE GUARANTEE THAT WE NEVER TRANSFER OR SELL YOUR DATA TO THIRD PARTIES OR COMMERCIAL PARTNERS.
Can your personal data be transferred outside the European Union?
The personal data processed by our platform are exclusively hosted on servers located within the European Union.
In addition, we make every effort to use only technical tools whose servers are also located within the European Union. If this is not the case, we ensure that appropriate safeguards are implemented to guarantee the confidentiality and protection of your personal data.
How do we protect your personal data?
We implement technical and organizational measures to ensure the security of your personal data daily, and in particular to prevent any risk of destruction, loss, alteration, or unauthorized disclosure.
Do we use cookies when you browse our platform?
WE GUARANTEE THAT WE DO NOT USE ANY ADVERTISING COOKIES FOR THE OPERATION OF THIS PLATFORM.
However, we inform you that we use statistical cookies when you browse our platform. For more information, please refer to our Cookie Policy.
Who can you contact for more information about the use of your personal data?
To best ensure the protection and integrity of your data, we have officially appointed an independent Data Protection Officer (“DPO”) with our supervisory authority.
You may contact our DPO at any time and free of charge at dpo@synneo.fr for more information or details about how we process your data.
How can you contact the CNIL?
You may contact the “Commission Nationale de l’Informatique et des Libertés” (“CNIL”) at any time at the following address:
CNIL Complaints Department, 3 Place de Fontenoy – TSA 80751, 75334 Paris Cedex 07
Phone: +33 (0)1 53 73 22 22
Can the Privacy Policy be modified?
We may amend our Privacy Policy at any time to reflect new legal requirements or new types of data processing that we may implement in the future.