Privacy Policy
1. Purpose of the Privacy Policy
The purpose of this privacy policy is to inform you, in a clear, concise and transparent manner, of how ANGHELLO collects, uses, stores and protects personal data when users access its services, including the website www.anghello.com (hereinafter: the SITE), the client application app.anghello.co (hereinafter: the CLIENT APP) and the visitor application spot.anghello.co (hereinafter: the VISITOR APP). ANGHELLO is committed to respecting the confidentiality of data and to guaranteeing its security in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act (loi Informatique et Libertés).
More specifically, this policy aims to:
- Describe the types of personal data collected and the reasons for such collection.
- Explain how ANGHELLO uses personal data.
- Detail the measures taken by ANGHELLO to protect the confidentiality and security of data.
- Indicate how ANGHELLO shares data with third parties and the safeguards in place to protect such information.
- Inform users of their rights regarding the protection of personal data and of how to exercise them.
- Inform users of any change to this privacy policy and of how such changes will be communicated.
2. Data controller
As publisher of the SITE, the CLIENT APP, the VISITOR APP and the associated services, ANGHELLO, SAS, EU VAT number FR91930696273, whose registered office is located at 8 rue des chenes, 39700 RANS, France, is the controller of the personal data collected when you browse the SITE and when you use its applications and services.
3. Collection of Personal Data
Categories of Personal Data concerned
ANGHELLO collects and processes various categories of personal data required to provide and improve its services. This data includes:
- Identification data: such as surname, first name, email address, company name and address, company website and other similar information allowing the user to be identified.
- Login data: including login credentials, country of connection, login logs and other data used to ensure the security and integrity of user accounts.
- Usage data: cookies and browsing data such as pages visited, actions performed, features used and browsing logs.
- Technical data: technical information such as browser type, operating system, IP address, country of connection and other similar data collected while using our services in order to ensure their security and integrity.
- Communication data: correspondence exchanged with customer service; feedback collected; satisfaction surveys and other interactions with the user.
- Financial data: information required to process payments, such as bank details, billing information and financial transactions.
If you register on the VISITOR APP during a visit to one of our clients, this policy does not apply to you. Our clients act as the data "controller", which means that they collect the information required for the purposes of your visit to their premises. If you wish to exercise your rights over the data they hold, you must contact them directly.
Purposes of data collection via the SITE
Your data is processed mainly for the following purposes:
| Purposes of data collection | Personal Data concerned | Legal basis for processing |
|---|---|---|
| the proper functioning and continuous improvement of the SITE | Technical data, Usage data | Consent, Legitimate interest |
| handling appointment requests | Identification data | Consent |
| handling requests to download documents and white papers produced by ANGHELLO | Identification data | Consent |
| producing traffic statistics | Technical data, Usage data | Consent, Legitimate interest |
Purposes of data collection via the CLIENT APP
| Purposes of data collection | Personal Data concerned | Legal basis for processing |
|---|---|---|
| Creating and managing your account | Identification data, Login data | Consent upon account creation, Performance of the contract |
| Managing your subscription | Identification data, Login data, Technical data, Financial data | Consent, Performance of the contract |
| Setting up and sending you tips and advice about our services electronically | Identification data, Login data, Usage data | Consent |
| Ensuring service continuity and maintaining a secure environment | All data required for security purposes | Legitimate interest |
| Providing customer support | Identification data, Login data, Communication data | Performance of the contract |
Purposes of data collection via the VISITOR APP
If you register on the VISITOR APP during a visit to one of our clients, this privacy policy does not apply to you. Our clients act as data "controllers", which means that they collect the information required for the purposes of your visit to their premises. ANGHELLO acts solely as a "processor", providing the tools and services required for this data collection.
The data collected may include your surname, first name, email address, telephone number, company name, arrival and departure times, as well as any other information required by the client. This data is collected and used in accordance with each client's own privacy policy.
If you wish to exercise your rights over the data held by our clients, including the right of access, rectification, erasure or objection, you must contact them directly. ANGHELLO cannot intervene directly in the handling of these requests, but undertakes to provide its clients with all the assistance they need to respond to your requests in accordance with the applicable regulations.
4. Recipients of Personal Data
ANGHELLO ensures that personal data is accessible only to authorised recipients, whether internal or external. Your data is neither disclosed, exchanged, sold nor rented to third parties other than those mentioned below. Only the authorised recipients specifically designated below may access the personal data collected:
Internal recipients
The personal data collected by ANGHELLO is accessible only to authorised employees who need it to carry out their duties. The main internal recipients include:
- Customer Service and Technical Support: access to the information required to provide technical assistance and respond to user requests.
- Marketing and Communication: access to data in order to send commercial information and newsletters, in compliance with users' consent and communication preferences.
- Administration and Accounting: access to financial data for the management of invoices, payments and subscriptions.
- Development and IT: access to data to ensure the maintenance, security and continuous improvement of the applications and the website.
External recipients
ANGHELLO may also share personal data with third parties in the following cases:
- Service Providers and Processors: hosting and storage of the CLIENT APP and VISITOR APP data (Scaleway SAS, servers located in France); delivery of the SITE through a content delivery network (Vercel Inc., a company established in the United States, certified under the EU-U.S. Data Privacy Framework, whose points of presence in use are located in France and Germany); providers of maintenance, security, payment, marketing and other services required to operate the applications and the website.
- Business Partners: ANGHELLO may share data with business partners for the marketing, promotion or distribution of its services.
- Administrative and Judicial Authorities: ANGHELLO may be required to disclose personal data in order to comply with a legal obligation or a request from an administrative or judicial authority, or to protect its rights and interests.
- ANGHELLO's Clients: visitor data recorded during visits to ANGHELLO's clients is transmitted to those clients, who act as data controllers in accordance with their own privacy policies.
ANGHELLO ensures that all external recipients comply with data confidentiality and security standards and use personal data only for the specific purposes for which it was shared. Data processing agreements (DPA - Data Processing Agreement) are put in place to guarantee this protection.
5. Retention period of Personal Data
ANGHELLO retains your personal data only for as long as necessary for the purposes for which it was collected, in accordance with the applicable legal requirements.
- Account data: data relating to Users and Clients (Identification data and Login data) is retained for the entire period of use of the Services and is deleted within three (3) months of the account being deactivated.
- Subscription data: data relating to subscriptions and transactions is retained for the duration of the contractual relationship and may be retained and archived for a period of five (5) years after the end of that relationship.
- Loyalty and prospecting data: data used for customer loyalty and commercial prospecting purposes is retained for a maximum of three (3) years from its collection or from the last contact initiated by the Prospect.
- User experience data: data collected to improve the user experience and optimise our Services (Usage data), such as cookies, may be retained for a maximum of 13 months from its collection or from the last expression of consent.
- Technical data (login data and cookies): login data (IP addresses and logs of the Data Subjects) is retained for a period of one (1) year from the last login or the last use of ANGHELLO's services.
- Financial data: financial data, such as payment details, is processed by a payment service provider through ANGHELLO's services. This provider ensures the secure hosting and management of financial transactions relating to the payment of subscription fees and additional services. Personal information, including bank card numbers, is collected and retained by this provider only for as long as necessary to carry out payment operations. ANGHELLO never has access to this payment information.
Data used to establish proof of a right or a contract (such as client data) or retained to comply with legal obligations (such as billing data) is retained for as long as necessary for the purposes for which it was collected, in accordance with the legislation in force. Once these periods have expired, the data is either deleted or anonymised for statistical purposes.
6. Rights of Data Subjects
In accordance with the French Data Protection Act and the GDPR, Data Subjects have the following rights:
- Right of access (Article 15 of the GDPR): they may exercise their right of access in order to know which Personal Data concerning them is held.
- Right to rectification (Article 16 of the GDPR): if the Personal Data held by ANGHELLO is inaccurate or incomplete, they may request that the information be updated.
- Right to erasure (Article 5 of the GDPR and Article 17 of the GDPR on the erasure of data or "right to be forgotten"): Data Subjects may request the deletion (in whole or in part) of their Personal Data, in accordance with the applicable data protection regulations.
- Right to restriction of processing (Article 18 of the GDPR): Data Subjects may ask ANGHELLO to restrict the processing of their Personal Data in the cases provided for by the GDPR.
- Right to object to data processing (Article 21 of the GDPR): Data Subjects may object at any time to the processing of their Personal Data on grounds relating to their particular situation, in accordance with the provisions of the GDPR.
- Right to data portability (Article 20 of the GDPR): they may request a copy of the personal data they have provided.
To exercise these rights, requests may be sent by email to privacy@anghello.co or by post to ANGHELLO, 8 rue des chenes, 39700 RANS, France, including full contact details (surname, first name, address) and a signed copy of an identity document as proof of identity, together with, where applicable, a legitimate reason as required by law (in particular in the case of an objection to processing).
The copy of the identity document will be retained for a period of one (1) year, or three (3) years in the case of an objection to processing, for identity verification purposes.
For further information, the website of the French data protection authority (Commission Nationale de l’Informatique et des Libertés, CNIL) is available at: http://cnil.fr.
7. Security of Personal Data
As Data Controller, ANGHELLO undertakes to comply with European regulations and to maintain an appropriate level of security in line with the requirements of the GDPR, as follows:
- No Personal Data is resold by ANGHELLO, even in anonymised form and for any purpose whatsoever.
- Only authorised staff members may access Personal Data, and only to the extent that they need it to carry out their duties.
- Personal Data processed by the CLIENT APP and the VISITOR APP is stored on servers hosted by Scaleway SAS within the European Union, in France, in Paris. The SITE is delivered through Vercel Inc.'s network from points of presence located in France and Germany; the technical browsing data passing through it is covered by this provider's EU-U.S. Data Privacy Framework certification (Article 45 of the GDPR).
- Personal Data may be anonymised or deleted through established procedures in order to guarantee the protection of the rights of the data subjects.
8. Conditions of application
Continuing to browse the SITE and using the services and applications implies full and complete acceptance of the provisions of this Privacy Policy.
This Privacy Policy may be modified at any time to reflect changes in our practices or in response to legal or case-law developments or decisions of the CNIL. Any update to this Policy will be communicated to the persons concerned by appropriate means, such as a notification on our SITE or by email.
This Privacy Policy is a translation of the French original, which is the authoritative version. In the event of any discrepancy between the two versions, the French version shall prevail.