Effective Date: June 30, 2024
Introduction
This privacy policy (the “Privacy Policy”) is established by IWD, having its registered office located at 77 rue du Faubourg Saint-Antoine 75011 Paris France, registered under the number 429 080 526 RCS Paris, in its capacity of data controller.
IWD has appointed a data protection officer who can be reached at the following address: gdpr@iwd.io.
Our Privacy Policy explains the data we collect, how we use it, how to manage your privacy controls and your rights in connection with our website and the related mobile application and services (collectively, the “Service”).
This policy was written in English. To the extent a translated version conflicts with the English version, the English version prevails.
Questions or comments about this Privacy Policy may be submitted by our contact form found here.
Data Processed
The use of the Service implies we collect and process information about you, including information that directly or indirectly identifies you.
Account, Profile, Activity, and Use Information
We collect basic account information such as your name, email address, contact number and profile picture (optional) to provide you with access to our Services.
Activity and use information is collected when you access the Service, in particular login details and navigation data related to the use of the Services or when you contact the support service.
Location Information
When you use our mobile application, and subject to your prior consent, we collect and process location information when you use the Service for informing you about the nearest shops. We do not track your device location while you are not using the Service.
Third-Party Authentication
The Service allows you to log in using accounts created with third-party products and services, such as Google, Azure and other Authentication Providers (collectively, “Third-Party Accounts”). If you access the Service with Third-Party Accounts we will collect information that you have agreed to make available such as your name and email address. This information is collected by the Third-Party Account providers and is provided to the Service under their privacy policies. You can generally control the information that we receive from these sources using the privacy controls in your Third-Party Account.
Technical Information and Log Files
We collect information from your browser, computer, or mobile device, which provides us with technical information when you access or use the Service. This technical information includes device and network information, cookies, log files and analytics information. Learn more about how we use cookies and manage your preferences by visiting our Cookie Policy.
The information stored in log files includes IP addresses, browser type, internet service provider (ISP), referring/exit pages, platform type, date/time stamp, and number of clicks. This information is used to analyze trends, administer, protect and secure the Service, track user movement in the aggregate, and gather broad demographic information (e.g., country residence) for aggregate use. IP addresses may be linked to session IDs and device identifiers.
Other Information
We may collect information directly from you or through our service providers, such as when we collect your feedback through surveys.
How We Use your Data and for how long
Purposes
|
Legal basis
|
Retention period
|
To provide the Service We use the information we collect and receive to provide the Service |
Contract execution |
As long as the account is active, then retention for a 5 year-period for evidentiary purposes
|
To protect you and the Service We use the information we collect and receive to protect users and our service, to monitor usage for Services resources and malicious or fraudulent activity.
|
Our legitimate interest in ensuring the proper functioning of the Service and its security | Logging of technical connection logs / user actions is kept for a period of 12 months |
To assist you with a support request We use the information we collect and receive to provide support in response to your requests and comments. Depending on your request, this may require us to access your account, for example, to troubleshoot or replicate a reported issue.
|
Contract execution |
As long as the account is active, then retention for a 5 year-period for evidentiary purposes
|
To customize your experience We may use your localisation data to provide you with additional information, in particular the localisation of the nearest shops |
Consent | Data kept for the duration strictly necessary for the result to appear |
To communicate with you We may also use the information we collect and receive to promote the Service , including using email, push notifications and website alerts. We may also contact you for feedback or to send proactive customer support messages. |
Our legitimate interest | 3 years from last contact |
Pre-litigation and litigation management
We use your personal data to litigation and pre-litigation management
|
Our legitimate interest | In the context of pre-litigation and litigation management, data is deleted as soon as the dispute has been settled out of court or, failing that, as soon as the corresponding legal action has become time-barred (until all ordinary and extraordinary remedies have been exhausted). |
To manage your rights
|
legal obligation | Data relating to the management of requests for rights are kept for the duration necessary to process the request. It is then archived for the duration of the criminal statute of limitations applicable to intermediate archiving, 6 years. |
How Information is Shared
We do not sell your personal information, we do not share your personal information except when needed to run our business and provide the Service, and where required for legal purposes.
Service Providers
We may share your information with third parties who provide services to the Service such as supporting, improving, promoting and securing the Service. These service providers only have access to the information necessary to perform these limited functions on our behalf and are required to protect and secure your information.
Publicly Available Information
Access to the Service is for authorised users only, data is not made publicly available.
Sharing Information and Activities with the other Services users within your organisation
We share your information and activities within the Service with other Service users, this is strictly limited to companies which you are associated. Sharing information is fundamental to the Service and consists of but not limited to, Planograms, Exports, Profile Information, Access Logs and Data Auditing.
Subsidiaries and Acquirors of our Business or Assets
We may share your information with our subsidiaries when they are involved in the provision of the Services.
If Service becomes involved in a business combination, securities offering, bankruptcy, reorganization, dissolution or other similar transaction, we may share or transfer your information in connection with such transaction.
Legal Requirements
We may preserve and share your information with third parties, including law enforcement, public or governmental agencies, or private litigants, within or outside your country of residence, if we determine that such disclosure is allowed by the law or reasonably necessary to comply with the law, including to respond to court orders, warrants, subpoenas, or other legal or regulatory process. We may also retain, preserve or disclose your information if we determine that this is reasonably necessary or appropriate to: (1) prevent any person from death or serious bodily injury; (2) to address issues of national security or other issues of public importance; (3) to prevent or detect violations of usage or fraud (4) or to protect our operations or our property or other legal rights, including by disclosure to our legal counsel and other consultants and third parties in connection with actual or potential litigation.
Exercising Your Rights
You have the following rights:
- Right of access: you may obtain the confirmation that your personal data are or are not processed by us and, when your data are processed, you may obtain access to such personal data and to a number of information items.
- Rectification right: you may obtain the rectification of those of your personal data that are inaccurate, and you may obtain that any incomplete data concerning you be supplemented.
- Right to erasure (“right to be forgotten”): under the conditions and within the limits provided for by applicable regulations, you may obtain the erasure of your personal data.
- Right to restriction of processing: under the conditions and within the limits provided for by applicable regulations, you may obtain the limitation of the processing of your data.
- Right to data portability: under the conditions and within the limits provided for by applicable regulations, you may receive the personal data concerning you which you have provided to us, in a structured, commonly used and machine-readable format, and you have the right to transmit those data to another controller.
- Right to object: when the processing of your personal data is necessary for our legitimate purposes, you may, within the limits provided for by applicable regulations, object at any time to such processing. You may also at any time object to the processing of your personal data for canvassing purposes.
- Right to withdraw your consent: when the processing of your personal data is based on your consent, you may withdraw your consent at any time.
- Right to give instructions on the handling of your data after your death: you may define and communicate to us specific instructions concerning the conservation, erasure and communication of your personal data after your death.
- Some of these rights may directly be exercised. In particular: You may access, correct, amend or update profile or account information at any time by adjusting that information in your account settings.
- You can choose to stop receiving certain email notifications by indicating your preferences within Execute and the IWD App.
For exercising your other rights, please submit your request at gdpr@iwd.io.
For information, you can delete your account by contacting your Company Service Administrator by sending a request via our contact form.
If, after contacting us, you consider that your rights are not complied with, you may send a complaint to the competent national authority.
How We Protect your Data
We implement technical, physical, and organizational measures and controls to safeguard and protect the transmission and storage of the data we collect. We employ reasonable protections for your information that are appropriate to its sensitivity.
Please be aware that despite our efforts, we cannot guarantee absolute security of your account or information. In addition, you can take steps to protect your account and information such as creating a unique password for the Service that is not easily guessed and that you don't use anywhere else, not sharing your password with others, and promptly reporting suspicious activity or unauthorized account access.
Cross Border Data Transfers
The Services are operated from the EU and the United States. If you are located outside of these zones and choose to use the Service or provide information to us, you acknowledge and understand that your information will be transferred, processed and stored within these zones, as it is necessary to provide the Service.
Whenever we transfer personal data internationally, we use legal mechanisms to ensure data transfers comply with applicable law. In particular, We use the appropriate legal mechanisms like the European Commission’s Standard Contractual Clauses specially designed for this type of transfer and take all necessary measures and guarantees to secure such transfers according to applicable law.
Privacy Policy Updates
IWD reserves the right to modify this Privacy Policy at any time. Please review it occasionally. If IWD makes changes to this Privacy Policy, the updated Privacy Policy will be posted in a timely manner. If we make changes we deem to be material, we will provide a prominent notice. If you object to any changes to this Privacy Policy, you should stop using the Services and delete your account.