1. What is the purpose of this Policy?
We attach great importance to the protection and confidentiality of your personal data, which represent for us a guarantee of seriousness and trust.
If you are under 15 years of age, you are not permitted to use our services without the prior express consent of one of your parents, which must be provided in writing to firstname.lastname@example.org. If you believe that we may be holding information about a child of yours under the age of 15 without your consent, you may request that we delete that information at the service address email@example.com.
3. Why do we process your data?
As part of the services offered, we may need to process your personal data for the following reasons and purposes:
- • To use MyHooky app mobile and benefit from our analysis services and so that we can respond to your requests (e.g., requests for information, complaints, etc.) on the basis of our terms and conditions of sale, our terms and conditions of use, and our legitimate interest in providing you with the best possible service.
- • To use your health personal data identified with the help of our device in order to provide you with results on the basis of your prior consent.
- • To ensure and enhance the security and quality of our services on a day-to-day basis (e.g. statistics, data security, etc.) based on our legal obligations, our terms and conditions and our legitimate interest in ensuring the proper functioning of our services.
Your data is collected directly from you when you log on to our website and use our services.
We never carry out commercial canvassing (e.g. emailing, sending SMS, etc.) as part of our activity and we undertake to process your data only for the reasons described above.
4. What data do we process and for how long?
We have summarized the categories of personal data we collect and their respective retention periods.
If you wish to obtain further details on the retention periods applicable to your data, you can contact us at: firstname.lastname@example.org.
- • Personal identification data (e.g. name, first name) and contact information (e.g. personal email address) kept for the duration of the activation of your account.
- • Health data (e.g., illness, disability, etc.) retained for the duration of the activation of your account.
- • Connection data (e.g. logs, IP address, etc.) kept for 1 year.
Upon expiration of the retention periods summarized above, we delete all of your personal data to ensure your privacy for future years.
The deletion of your personal data is irreversible, and we will no longer be able to communicate them to you after this period. At most, we can only keep anonymous data for statistical purposes.
Please also note that in the event of litigation, we are required to retain all of your data for the duration of the processing of the case even after the expiration of the retention periods described above.
5. What rights do you have to control the use of your data?
The applicable data protection regulations give you specific rights that you can exercise, at any time and free of charge, to control how we use your data.
● Right of access and copy of your personal data as long as this request is not in contradiction with business secrecy, confidentiality, or the secrecy of correspondence.
● Right to rectify personal data that are incorrect, outdated or incomplete.
● Right to object to the processing of your personal data carried out for commercial prospecting purposes.
● Right to request deletion (« right to be forgotten ») of your personal data that is not essential for the proper functioning of our services.
In order for a request to be processed, it must be made directly by you at email@example.com. Any request that is not made in this way cannot be processed.
Requests cannot be made by anyone other than you. Therefore, we may ask you to provide proof of identity if there is any doubt about the identity of the applicant.
We will respond to your request as soon as possible, but no later than three months from receipt of the request, in case the request is technically complex or if we receive many requests at the same time.
Please note that we may always refuse to respond to any excessive or unfounded request, especially if it is repetitive.
6. Who can access your data?
We will only share your data with persons duly authorized to use it to implement our services. This may include our staff in charge of the implementation of the service, our technical providers (e.g. data hosting) or even the security of our premises.
7. How do we protect your data?
We implement all technical and organizational means required to guarantee the security of your data on a daily basis and, in particular, to fight against any risk of destruction, loss, alteration, or disclosure of your data that would not be authorized (e.g.: training, access control, password, antivirus, « https », etc).
8. Can your data be transferred outside the European Union?
Unless strictly necessary and on an exceptional basis, we never transfer your data outside the European Union and your data is always hosted in European soil. In addition, we make every effort to hire only service providers who host your data within the European Union.
Should our service providers nevertheless transfer your personal data outside the European Union, we take great care to ensure that they implement appropriate safeguards to ensure the confidentiality and protection of your data.
9. Who can you contact for more information?
Our Data Protection Officer (« DPO ») is always available to explain in more detail how we process your data and to answer your questions on the subject at firstname.lastname@example.org.
10. How can you contact the CNIL?
You may at any time contact the French data protection supervisory authority (the « Commission nationale de l’informatique et des libertés » or « CNIL ») at the following address CNIL Complaints Department, 3 place de Fontenoy – TSA 80751, 75334 Paris Cedex 07 or by telephone at 01.53.73.22.22.
11. Can the policy be changed?