Privacy Policy and Personal Data Protection of OLIVESOFT
At OLIVESOFT, the protection of your personal data and compliance with applicable regulations â in particular the General Data Protection Regulation (GDPR) â are of paramount importance to us. As part of our IT services, we may access our clients' systems and data, thereby acting as a data processor. This privacy policy is set out within that context.
This privacy policy also defines and informs you of how OLIVESOFT uses and protects the information you provide to us, where applicable, when you use this website accessible at the following URL: https://olivesoft.fr/ (hereinafter the "Website").
Please note that this privacy policy may be modified or supplemented at any time by OLIVESOFT, in particular to comply with any legislative, regulatory, case-law or technological developments. In such a case, the date of its update will be clearly identified at the top of this policy. These modifications are binding on the User as soon as they are published online. The User should therefore regularly consult this privacy and cookie policy to be aware of any changes.
Part I â General Provisions
Article 1. Definitions
- "OLIVESOFT", "we", "our", "us" refer to the company OLIVE-SOFT, registered under SIREN number 843 934 860, a Simplified Joint Stock Company (SAS), with its registered office at 42, rue de Maubeuge, 75009 Paris, France.
- Data Controller: means the entity that determines the purposes and means of the Processing of Personal Data.
- Data Processor: means the entity that Processes Personal Data on behalf of the Data Controller and in accordance with its instructions.
- Data Protection Regulations: means all European and national regulations relating to privacy and Personal Data, in particular EU Regulation No. 2016/679 of 27 April 2016 (GDPR) and French Law No. 78-17 of 6 January 1978 as amended, and any other law provided for in the service agreement signed by the Client.
- Data Protection Authority: means the supervisory authority concerned with the processing of Personal Data. Where processing affects individuals in several EU Member States, the supervisory authority of the main establishment of the Data Controller shall be considered the lead supervisory authority, in accordance with the GDPR.
- Personal Data: means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.
- Processing (or Process): means any operation or set of operations performed on Personal Data, such as collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, making available, alignment, erasure or destruction.
- OLIVESOFT Client(s): refers to the clients of OLIVESOFT who have entered into a service agreement with the company.
- Service Agreement: means the legal agreement entered into between OLIVESOFT as service provider and its client, whereby OLIVESOFT undertakes to provide specific services in exchange for remuneration. This agreement also formalises the conditions under which OLIVESOFT, as service provider, may access the client's personal data in order to perform the agreed services.
Article 2. Security Measures
OLIVESOFT may act either as a Data Controller or as a Data Processor depending on the circumstances. As a Data Controller, OLIVESOFT determines the purposes and means of the processing of personal data and is responsible for ensuring that such processing complies with applicable legal and regulatory obligations. As a Data Processor, OLIVESOFT processes personal data on behalf of a client under a service agreement, in accordance with the Data Controller's instructions and applicable contractual and legal data protection obligations, including security and confidentiality.
OLIVESOFT implements and maintains appropriate technical and organisational security measures to protect the confidentiality of the Personal Data it processes or to which it has access, in accordance with the requirements of the Data Protection Regulations.
These measures take into account the potential risks to the individuals concerned arising from the processing carried out. They comply with industry standards and security best practices, and take into account the recommendations of Data Protection Authorities.
OLIVESOFT endeavours to:
- Ensure it has physical security measures in place against malicious acts or cyberattacks.
- Protect access to the client's systems by OLIVESOFT personnel through strong authorisation and authentication measures. Operating system security updates are installed on a regular basis. Technical measures are in place to guard against malicious software.
- Implement and maintain security and confidentiality measures that take into account the principles of Personal Data protection and are adapted to the risks posed by their processing to the rights and freedoms of individuals concerned, in accordance with the requirements of the applicable Regulations. These measures aim to protect Personal Data against destruction, loss, alteration, disclosure to unauthorised third parties, and to ensure the restoration of availability and access to Personal Data within appropriate timeframes in the event of an incident.
In the event of a failure, OLIVESOFT will make every effort to restore the service as quickly as possible, within the limits of its commitments.
Part II â Processing of Personal Data for which OLIVESOFT acts as Data Processor
Article 3. Identification of Processing Activities
For the purposes of providing the Services and more generally to carry out any other tasks assigned by the Client under the Service Agreement, OLIVESOFT may be required to process the Personal Data that the Client integrates into its IT systems.
| Data Subject | Purpose of Processing | Legal Basis | Categories of Data Processed | Retention Period |
|---|---|---|---|---|
| Any individual whose Personal Data is collected or processed by the OLIVESOFT Client | Purposes are determined by the OLIVESOFT Client | Performance of the Agreement between the Client and the Data Subject | All categories, depending on the processing activities carried out by the Client as Data Controller | Duration of the Agreement with the Client or any other retention period requested by the Client |
Article 4. OLIVESOFT's Commitments
In its capacity as Data Processor, OLIVESOFT undertakes to comply with the following obligations and to ensure that its personnel comply with the same obligations, in accordance with Article 28 of the GDPR:
- (a) Process the Personal Data collected by the Client solely for the purposes of providing the Services defined in the Agreement;
- (b) Ensure the confidentiality of Personal Data and ensure that its authorised personnel are bound by a confidentiality obligation;
- (c) Take into account, with regard to its tools, products, applications or services, the principles of data protection by design and by default;
- (d) Not use Personal Data for purposes other than those set out in the Agreement and not retain it beyond the end of the Agreement or any other duration specified by the Client;
- (e) Return Personal Data under the conditions set out below;
- (f) Not grant a licence, lease or transfer Personal Data, in whole or in part, to any third party without the prior written consent of the Client;
- (g) Reasonably assist the Client in carrying out privacy impact assessments where necessary;
- (h) Respond as promptly as possible to any request from the Client relating to the Personal Data processed, in order to enable the Client to address, within the required timeframes, any requests from Data Subjects (right of access, rectification, erasure, objection, etc.);
- (i) Notify and assist the Client in ensuring compliance with obligations relating to the security of Personal Data, particularly in the context of security breach notification procedures, under the conditions set out below;
- (j) Implement technical and organisational measures enabling the Client to fully comply with the rights of Data Subjects, including the right of access, rectification or erasure of Personal Data, restriction of processing, the right to object to decisions based on profiling, and the right to data portability where applicable;
- (k) Define and formalise a policy governing the return and destruction of personal data, and make it available to the Client upon request.
The Client is informed that if OLIVESOFT is required to disclose Personal Data to a law enforcement body, OLIVESOFT will make every effort to give the Client reasonable prior notice and allow it to seek a protective order or other appropriate remedy, unless OLIVESOFT is prohibited from doing so by law or by the competent Data Protection Authority.
Article 5. Location of Personal Data
Personal Data is not stored within OLIVESOFT's own infrastructure, but is stored in the Client's data centres and IT systems in accordance with applicable legal provisions.
OLIVESOFT nonetheless has access to this data in the context of performing the service agreement. This access is necessary to enable OLIVESOFT to provide the agreed services and meet its clients' needs. OLIVESOFT's access to clients' personal data is therefore within the legal framework of the service agreement and is limited solely to the needs of performing the agreed services.
Article 6. Personal Data Breaches
If OLIVESOFT becomes aware of a Personal Data breach, it will notify the Client as promptly as possible after becoming aware of it and will provide all necessary information to enable the Client to assess the breach.
In accordance with Article 33 of the GDPR, unless the breach is unlikely to result in a risk to the rights and freedoms of Data Subjects, the Client, as Data Controller, shall be responsible for notifying the supervisory authority and, if the breach is likely to result in a high risk to their rights and freedoms, the affected individuals, in each relevant Member State. This notification must be made without undue delay and no later than 72 hours after the Client becomes aware of a Personal Data breach.
The Client's notification to the supervisory authority must:
- Describe the nature of the Personal Data breach and include, where possible, the categories and approximate number of individuals affected, and the categories and approximate number of Personal Data records concerned;
- Communicate the name and contact details of the data protection officer or other contact points from which further information can be obtained;
- Describe the likely consequences of the Personal Data breach;
- Describe the measures taken or proposed to address the Personal Data breach, including measures to mitigate its possible adverse effects.
Article 7. Record of Processing Activities
OLIVESOFT maintains a record of processing activities carried out on behalf of the Client, identifying, for itself and each of its sub-processors, the processing activities performed on behalf of the Client, the location from which the service is provided, and any transfers of Personal Data outside the European Economic Area (EEA). The record will also document, where applicable, the implementation of appropriate safeguards to ensure an adequate level of protection, and any other information required by the Data Protection Regulations. The record will be accessible at all times to the Client and the Data Protection Authority.
Article 8. Security and Confidentiality of Processing
The general security requirements are set out in Article 2 above.
With regard to the security of Personal Data processed for the purposes of providing the Services, OLIVESOFT implements additional measures arising from the Data Protection Regulations. In particular, OLIVESOFT undertakes to implement the following measures:
- Ensure adequate protection of Personal Data to guarantee its confidentiality and prevent Personal Data breaches and/or minimise the impact in the event of a breach;
- Ensure that any person acting under OLIVESOFT's authority who may have access to Personal Data for the purposes of their work does not carry out any other processing thereof, except in cases expressly authorised by the Client;
- Delete Personal Data at the end of the retention or access period defined by the Client.
Article 9. Sub-processors
The Client expressly authorises OLIVESOFT to sub-contract to its subsidiary the performance of tasks involving the processing, in whole or in part, of Personal Data within the scope of the Services.
OLIVESOFT undertakes to notify the Client of any planned changes concerning the appointment or replacement of a sub-processor and to give the Client the opportunity to object to such change in writing within 8 calendar days. The Client may only object to the new sub-processor on the following grounds: (i) the new sub-processor is a direct competitor of the Client; (ii) the new sub-processor is engaged in an ongoing dispute with the Client; (iii) the Client considers that the new sub-processor does not comply with the Data Protection Regulations; (iv) the replacement of the sub-processor would reduce existing security measures.
In any event, OLIVESOFT guarantees that any sub-processor it appoints offers sufficient guarantees to implement appropriate technical and organisational measures to meet the requirements of the Data Protection Regulations.
Processing by a sub-processor is governed by a contract between OLIVESOFT and the sub-processor that sets out the same rights and obligations as those defined herein, including the obligation to ensure the security of processing, the protection of Personal Data and the right to audit. OLIVESOFT will regularly verify, including through audits, that its sub-processors comply with the aforementioned obligations.
Furthermore, for transfers of Personal Data outside the European Economic Area (EEA), OLIVESOFT will ensure that these contracts include the standard contractual clauses approved by the European Commission to ensure an adequate level of protection for the transferred Personal Data.
OLIVESOFT maintains an up-to-date list of sub-processors specifying (i) their name and contact details, (ii) the nature of the tasks entrusted to them, (iii) the location of processing, and (iv) the dates of previous audits.
In all cases, OLIVESOFT remains fully responsible to the Client for the performance of its sub-processors' obligations.
Article 10. Documentation
OLIVESOFT will provide the Client, subject to confidentiality obligations, with all information necessary to demonstrate its compliance with the obligations under the Data Protection Regulations.
Article 11. Return and Deletion of Data
At the end of the Service Agreement, OLIVESOFT undertakes to return or delete the Personal Data.
Article 12. Client's Obligations
As Data Controller, the Client must ensure that Users and Data Subjects have been informed of the processing of their Personal Data and have given their consent where required. The Client warrants to OLIVESOFT compliance with the Data Protection Regulations in this regard (including in particular complete, intelligible and easily accessible information to Data Subjects; an appropriate legal basis for processing; and compliance with all required procedures and formalities, such as carrying out an impact assessment where applicable, etc.).
If the Client acts as a Data Processor on behalf of a third-party Data Controller, the Client warrants to OLIVESOFT that it has:
- (i) obtained all necessary authorisations to enter into the Service Agreement;
- (ii) ensured that the agreement entered into with the Data Controller is consistent with applicable regulations;
- (iii) ensured that the instructions given to OLIVESOFT are consistent with the Data Controller's instructions.
Article 13. Client's Warranties
The Client warrants that it has obtained and will maintain all consents and/or declarations/authorisations necessary to lawfully Process the Personal Data of Users and Data Subjects.
The Client shall indemnify and hold harmless OLIVESOFT against any claim or action by a User or Data Subject in relation to the protection of their Personal Data.
Article 14. Liability
It is recalled that OLIVESOFT is subject to a best-efforts obligation in the provision of Services to the Client. OLIVESOFT's liability towards the Client may only be engaged in the event of direct damage suffered by the Client caused by a proven contractual breach by OLIVESOFT committed in or in connection with the performance of its obligations.
Without prejudice to the foregoing, the Client expressly acknowledges and accepts that OLIVESOFT's liability may in no circumstances be engaged in respect of the processing of Personal Data carried out by the Client.
The Client, as Data Controller, is solely responsible towards third parties for compliance with the Data Protection Regulations and indemnifies OLIVESOFT against any action, claim or recourse by third parties (data subjects, supervisory authorities or other third parties) in this regard.
Pursuant to Article 82 of the GDPR, it is recalled that OLIVESOFT's liability, as Data Processor of the Client, is strictly limited to the contractual obligations undertaken under the service agreement. If both Parties were jointly found liable for damage caused to a data subject as a result of the processing of their data, OLIVESOFT shall only be required to compensate for the damage in proportion to its contractual liability towards the Client.
Part III â Processing of Personal Data for which OLIVESOFT acts as Data Controller
Article 15. Identification of Processing Activities
OLIVESOFT processes the following Personal Data as Data Controller:
OLIVESOFT collects, stores, processes, uses and communicates personal data about you when you use the "contact us" section of the website: https://olivesoft.fr/ (the "Website").
OLIVESOFT collects and processes the following categories of data: Identification and contact data: for example your identity, email address, telephone number.
OLIVESOFT collects data about you to respond to your online requests, questions and complaints. For this purpose, based on our legitimate interest, we ensure that we take into account any potential impact this collection may have on you and users of the Website in general. If we consider that your interests or fundamental rights and freedoms override our legitimate interest, we will not use your personal data on this basis and may ask for your specific consent.
Data is retained for a period that does not exceed the duration necessary for the purposes for which it was collected as described above. It will then be permanently deleted from our systems or anonymised so that you can no longer be identified or identifiable.
Article 16. Identification of Recipients of Processed Personal Data
In addition to the aforementioned sub-processors, OLIVESOFT may be required to communicate the Personal Data it processes to the following categories of recipients:
- OLIVESOFT staff members: for the performance of their duties, strictly as necessary for the provision of Services in accordance with the Agreement;
- Accounting firm: for the management of OLIVESOFT's accounting;
- Statutory auditor: for the certification of annual accounts;
- Administrative and/or judicial authorities: in the event of an audit of the company and/or a dispute involving the Client. In the latter case, OLIVESOFT will make every effort to give the Client reasonable prior notice and allow it to seek a protective order or other appropriate remedy, unless OLIVESOFT is prohibited from doing so by law or by the relevant authority.
Article 17. OLIVESOFT's Commitments
OLIVESOFT undertakes to process the Personal Data of the Client and Users in strict compliance with the Data Protection Regulations. To this end, OLIVESOFT implements and maintains security measures for the Platform and, more generally, for its IT systems, in compliance with the aforementioned Regulations, as further detailed in Article 2 above.
Personal Data is strictly confidential and intended exclusively for OLIVESOFT, which undertakes not to use Personal Data for any purpose other than those set out above. Only the recipients mentioned in Article 16 above may have access to Personal Data, solely for the purpose of performing their duties.
OLIVESOFT undertakes to retain the Personal Data processed for the retention period mentioned above.
Article 18. Transfers of Data outside the European Economic Area
The Client or User expressly acknowledges that certain sub-processors mentioned in Article 16 are affiliated companies of foreign groups located outside the European Economic Area. As a result, Personal Data may be transferred outside the EEA for technical reasons (e.g. platform management, remote maintenance, etc.) or due to a legal or regulatory request. OLIVESOFT will notify the Client as promptly as possible if such a request is made and will only transmit Personal Data to the authorities with the Client's express agreement. If such notification is not authorised (preservation of confidentiality or a judicial investigation), OLIVESOFT will notify the Client or User as soon as it is legally authorised to do so.
Outside these cases, OLIVESOFT undertakes to take all legal measures recognised as appropriate by the Data Protection Regulations to control the transfer concerned and ensure that it meets the requirements of the aforementioned Regulations.
Article 19. Rights of Data Subjects
The Client and each User have the following rights regarding their Personal Data:
- Right of access: to obtain confirmation that their Personal Data is being processed as well as certain information about the processing;
- Right to rectification: to obtain the rectification of their Personal Data when it is inaccurate or incomplete;
- Right to erasure: under the conditions set out in Article 17 of the GDPR, to obtain the erasure of their Personal Data when it is no longer necessary for the purposes for which it was collected, or where the Client or User objects to the processing of their Personal Data;
- Right to restriction of processing: to obtain restriction of processing of their Personal Data where the Client or User contests the accuracy of the data, where the retention period for Personal Data has expired but the Client or User still needs to retain it for the establishment, exercise or defence of legal claims, or where the Client or User has objected to the processing;
- Right to data portability: to receive the Personal Data the Client or User has provided to OLIVESOFT in a readable format, or to request that OLIVESOFT transmit the Personal Data the Client or User has provided to another data controller;
- Right to object: under the conditions of Article 21 of the GDPR, to object at any time, on grounds relating to their particular situation, to the processing of their Personal Data, in particular where such objection concerns direct marketing, including profiling;
- Withdrawal of consent: to withdraw consent to the future processing of their Personal Data by OLIVESOFT, where processing is based on consent;
- Right to lodge a complaint: to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés ("CNIL") if they consider that the processing carried out by OLIVESOFT constitutes a violation of their Personal Data. The CNIL can be contacted via an online form available at: https://www.cnil.fr/webform/nous-contacter
Article 20. Exercising the Rights of Data Subjects
You may exercise these rights or ask any question relating to the management of your personal data by contacting our Data Protection Officer by email at the following address: dpo@olivesoft.fr.