PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA IN THE USE OF THE COMPANY APPLICATION

 

Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”), as well as applicable national laws, this notice describes the processing of personal data of employees and collaborators in relation to the use of the company application.

 

1. DATA CONTROLLER

The Data Controller is JINGHI SAS, with registered office at 11 Place des Vosges, 75004 PARIS, contactable at privacy@lemaire.fr.

 

2. SCOPE OF APPLICATION

This notice applies to personal data processing activities carried out through the company application accessible to authorized users (employees and collaborators) following authentication.

 

3. CATEGORIES OF PERSONAL DATA PROCESSED

In the context of using the application, the following categories of personal data may be processed:

 

·         Identification data: user ID, name and surname

·         Professional data: role, workplace, store, or organizational unit

·         Usage data: interactions with the application, features used, generated events, usage time

·         Technical data: device and application environment information (e.g., operating system, app version, technical logs)

 

4. PURPOSES OF PROCESSING

Personal data are processed for the following purposes:

a) provision and operational management of the application functionalities
b) ensuring system security and preventing unauthorized or improper use
c) technical monitoring, maintenance, and troubleshooting
d) aggregated analysis and continuous improvement of services and functionalities

 

No systematic monitoring of individual employee activity is carried out for performance control purposes, except where strictly necessary for organizational, production, or security needs.

 

 

5. LEGAL BASIS FOR PROCESSING

The processing of personal data is based on:

·         Article 6(1)(b) GDPR – performance of the employment or collaboration relationship

·         Article 6(1)(f) GDPR – legitimate interest of the Controller in ensuring system security, proper functioning, and service improvement

 

Consent of the data subject is not the primary legal basis, as the employment relationship may not allow for freely given consent.

 

6. PROCESSING AND EMPLOYEE MONITORING REGULATIONS

Data processing is carried out in compliance with applicable labor laws, including regulations concerning remote monitoring of employees.

 

The tools used:

·         are necessary for performing work activities and/or ensuring system security

·         are not intended to monitor employees remotely

·         may generate data that can be used within the limits permitted by applicable laws

 

Any additional processing involving employee monitoring will be carried out in compliance with applicable legal safeguards (e.g., union agreements or authorization from competent authorities, where required).

 

7. PROCESSING METHODS

Processing is carried out using electronic and IT tools in accordance with the principles set out in Article 5 GDPR.

Appropriate technical and organizational measures pursuant to Article 32 GDPR are implemented, including:

·         access control systems

·         authentication mechanisms

·         logging and monitoring of system access

·         protection against unauthorized access

 

8. DATA RETENTION

Personal data are retained for no longer than necessary to achieve the purposes described above and in compliance with applicable legal obligations.

In particular:

·         usage data and logs: retained for a limited and proportionate period based on technical and security needs

·         other data: retained for the duration of the employment relationship and as required by law

 

9. RECIPIENTS OF PERSONAL DATA

Personal data may be processed by:

·         authorized internal personnel

·         IT service providers and infrastructure providers, acting as Data Processors pursuant to Article 28 GDPR

 

10. TRANSFERS OUTSIDE THE EU

Any transfers of personal data outside the European Economic Area will be carried out in accordance with Articles 44 et seq. GDPR, based on:

·         adequacy decisions of the European Commission, or

·         Standard Contractual Clauses (SCCs), or

·         other appropriate safeguards

 

11. DATA SUBJECT RIGHTS

Data subjects may exercise the rights set out in Articles 15–22 GDPR, including:

·         right of access

·         right to rectification

·         right to erasure (where applicable)

·         right to restriction of processing

·         right to object

 

12. RIGHT TO LODGE A COMPLAINT

Data subjects have the right to lodge a complaint with the competent Data Protection Authority pursuant to Article 77 GDPR.

 

13. NATURE OF DATA PROVISION

The provision of personal data is necessary for the use of the application and for the performance of work-related activities.

 

14. AUTOMATED DECISION-MAKING

No automated decision-making processes, including profiling, are carried out within the meaning of Article 22 GDPR.

 

By using the application, the user acknowledges that they have read and understood this Privacy Notice.