Privacy Policy
Summary
1 What is the GDPR?
2 Who are we?
3 Use of collected personal data
3.1 Purpose of collected personal data
3.2 Comments
3.3 Media
3.4 Contact forms
3.5 Cookies
3.6 Embedded content from other sites
4 Use and transmission of your personal data
4.1 Data retention periods
4.2 Your rights regarding your data
4.3 Transmission of your personal data
4.4 Contact information / Data Protection Officer (DPO)
5 How we protect your data
5.1 Storage location of personal data
5.2 Security of personal data
5.3 Procedures implemented in the event of a data breach
6 Third-party services that provide us with data
7 Automated marketing and/or profiling operations carried out using personal data
8 Display of information related to sectors subject to specific regulations
9 Right of access, rectification, or deletion of personal data
1. What is the GDPR?
The General Data Protection Regulation (GDPR) has been applicable since May 25, 2018, in the 28 countries of the European Union.
It applies to all companies (including Works Councils), administrations, and associations that process personal data and provide services to users in the European Union, regardless of the location of these organizations worldwide.
The objective of the GDPR is to “give citizens back control over their personal data, while simplifying the regulatory environment for organizations.”
It is based on the French “Informatique et Libertés” law of 1978 and strengthens its measures.
In France, the reference body for monitoring its application is the CNIL.
To find out everything about the GDPR, follow this link: https://www.cnil.fr/cnil-direct/question/reglement-europeen-sur-la-protection-des-donnees-que-faut-il-savoir
2. Who are we?
Our website address is: www.biason.fr
3. Use of collected personal data
3.1 Purpose of collected personal data
The collection of personal data through the various forms on the site is intended to:
• Contact individuals who have requested information or ordered a product on the site
• Send promotional offers and event invitations by email.
By submitting the form and checking the appropriate consent boxes on the form, the user expressly agrees to the processing of personal data for the purpose of the commercial relationship.
The collection of personal data through the Google Analytics audience tracking tool used on the site is intended to:
• Analyze user behavior on the site to measure audience and improve performance.
Google Analytics uses third-party cookies to distinguish users. Cookies are text files installed on the user’s terminal. They contain no nominative information, only randomly created identifiers.
By browsing the site, the user expressly agrees to the processing of personal data collected by Google Analytics for the purpose of analyzing user behavior to improve site performance.
3.2 Comments
When you leave a comment on our website, the data entered in the comment form, as well as your IP address and browser user agent, are collected to help us detect spam.
An anonymized string created from your email address (also called a hash) may be sent to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture will be visible to the public next to your comment.
3.3 Media
If you are a registered user and upload images to the website, we advise you to avoid uploading images containing EXIF GPS location data. Visitors to your website can download and extract location data from these images.
3.4 Contact forms
If you use a contact form on our site, your data will be recorded to allow the processing of your request. Data is kept for 24 months before being deleted.
3.5 Cookies
If you leave a comment on our site, you will be offered the option to save your name, email address, and website in cookies. This is purely for your convenience so that you do not have to fill in these details again if you leave another comment later. These cookies expire after one year.
If you visit the login page, a temporary cookie will be set to determine if your browser accepts cookies. It contains no personal data and is discarded when you close your browser.
When you log in, we will set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data. It simply indicates the post ID of the article you just edited. It expires after one day.
3.6 Embedded content from other sites
Articles on this site may include embedded content (e.g., videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content if you have an account and are logged in to that website.
4. Use and transmission of your personal data
4.1 Data retention periods
If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
Data collected via forms is kept for a period of 4 years from the submission of the form.
The cookies used by the Google Analytics audience measurement tool have the following lifespans:
_ga: 2 years
_gid: 24 hours
_gat: 1 minute
4.2 Your rights regarding your data
If you have an account or have left comments on the site, you can request to receive a file containing all the personal data we hold about you, including any data you have provided to us. You can also request the deletion of your personal data. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
4.3 Transmission of your personal data
Visitor comments may be checked through an automated spam detection service.
4.4 Contact information / Data Protection Officer (DPO)
The Data Protection Officer (DPO) is the person within the company responsible for ensuring the compliance of the company’s activities with the new European GDPR legal framework, cooperating with the supervisory authority, and ensuring the security of the collected data.
You can contact them using the contact form or by mail at:
BIASON
Rue de la Vallée d’Ossau
64121 SERRES CASTET
5. How we protect your data
5.1 Storage location of personal data
The site’s hosting servers are located exclusively in France, within the European Union.
Biason Company undertakes not to transfer any personal data to a state that is not a member of the European Community.
5.2 Security of personal data
The site is hosted on a secure server.
All pages are in secure HTTPS mode, TLS 1.2 / RSA 2048 bits (SHA256withRSA). This is a security protocol that encrypts the content of exchanges between the browser and the database servers. This prevents personal data entered and sent via forms from being easily read by third parties during transit.
However, no transmission or storage of personal data is ever completely infallible. Consequently, Biason Company undertakes to implement its crisis policy in the event of a critical data breach.
Personal data concerning you and collected by this site is intended solely for Biason Company and will only be used within the framework of the request specified via the form.
Under no circumstances will personal data entered and sent on forms be transmitted, rented, or marketed to third parties, excluding carriers who deliver orders where applicable.
Employees and subcontractors of Biason Company have signed a confidentiality agreement that obliges them to respect data confidentiality under penalty of sanctions.
5.3 Procedures implemented in the event of a data breach
In the event of a data breach concerning you, the Data Protection Officer will contact you as soon as possible, using the information in our possession, to notify you so that you can take protective measures if necessary.
6. Third-party services that provide us with data
No third-party service transmits data to us concerning the users of this website.
7. Automated marketing and/or profiling operations carried out using personal data
Not applicable.
8. Display of information related to sectors subject to specific regulations.
Not applicable.
9. Right of access, rectification, or deletion of personal data
In accordance with the French Data Protection Act of January 6, 1978, as amended, and the General Data Protection Regulation 2016/679 (GDPR), you have the right to access, rectify, and delete personal data concerning you, which you can exercise by using the contact form or by sending a letter to Biason Company.
The user also has the right to lodge a complaint with the CNIL at https://www.cnil.fr/