Preamble
HEXIS is committed to an ongoing process of protecting the privacy and personal data of its users, in compliance with European Regulation No. 2016/679, known as the General Data Protection Regulation (GDPR), as well as all applicable national laws and regulations regarding the protection of personal data (collectively referred to as "data protection laws and regulations").
The purpose of this Privacy Policy is to inform all individuals concerned (customers, Internet users, users of its services), hereinafter referred to as "you and your":
about the personal data that HEXIS collects,
about how it uses and discloses your data,
about how you can control the use and disclosure of your data,
and about how it protects your personal data. The HEXIS Privacy Policy applies in addition to the General Terms of Use and the General Terms of Sale of the websites, where applicable.
1- What personal data do we use?
HEXIS, as Data Controller, is required to collect, consult, use, modify, store, transmit, and delete Personal Data as part of its activities.
In accordance with Article 4 of the General Data Protection Regulation 2016/679 of April 27, 2016, the terms "Data" or "Personal Data" refer to any information relating to an identified or identifiable natural person (hereinafter referred to as "Data Subject"). An "identifiable natural person" is defined as a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity.
Personal data that may be collected directly by HEXIS may include, but is not limited to:
Civil status and identification data (last name, first name, telephone number, social security number, address, etc.)
Professional data (CV, education, training, etc.)
Economic and financial information (billing data, payment methods, etc.)
Contractual relationship history
Connection data (IP addresses, event logs, etc.)
Location data (travel, GPS data, mobile phone, access badge, etc.)
Any other Personal Data that may be relevant for the purposes stated below.
The personal data collected by HEXIS is, however, limited to that strictly necessary for the purposes set out below.
This Policy does not apply to third-party websites that may be mentioned on our websites.
2- What are the legal bases and purposes for processing your personal data?
2.1. Purposes of processing your personal data
Personal data is generally only collected for the purposes of the company's business, unless we need it for an additional purpose compatible with the original purposes. If your personal data must be processed for a purpose unrelated to the original purpose, HEXIS will inform you in advance and take the appropriate steps, in particular to explain the basis for this processing.
The information collected will be processed, in particular, but not limited to, the following purposes:
– Managing the execution of contracts or agreements with the customer
o Managing contracts, orders, invoicing, and accounting
o Managing applications
– Carrying out operations related to customer relationship management (satisfaction surveys, loyalty programs, etc.);
– Carry out operations related to commercial prospecting and the preparation of quotes;
– Carry out marketing or communication activities regarding HEXIS products or services (organizing competitions, lotteries, or any other promotional activities);
– Manage and process your requests for information or your application
– Manage and process complaints
o Manage after-sales service complaints
o Manage your requests to exercise your rights regarding personal data protection
o Manage disputes;
– Manage the settlement of invoices, unpaid bills, and disputes
– Improve certain aspects of our website and compile statistics (see cookies)
When collecting your data When processing personal data, you are informed of the mandatory nature of the information requested in order to benefit from a service, or of its optional nature, as well as the consequences of not providing data. You are also informed of how HEXIS will use your data and of your right to access, rectify, object, erase, transfer data, limit processing, and know the fate of your data after death.
2.2 Legal basis for the processing of your personal data?
Depending on the purpose of the processing, the legal basis will be:
The performance of a contract or pre-contractual measures for processing related to contract management, orders, invoicing, and customer/user relations for HEXIS services
The result of your consent, particularly for commercial prospecting of customers who are natural persons
You may withdraw this consent at any time by simply sending us an email to the following address: rgpd@hexisgroup.com.
The pursuit of our legitimate interests
Compliance with our legal and/or regulatory obligations, for tax-related processing, for example
3- Who are the recipients of the data?
The controller of your personal data is HEXIS, a simplified joint-stock company with a capital of €10,000,000, registered with the Montpellier Trade and Companies Register under number 351 372 677, whose registered office is located at ZI Horizon Sud – 34110 FRONTIGNAN, acting as Data Controller.
As all personal data is confidential, access to it is limited to certain internal and external recipients, in strict compliance with the purposes mentioned above:
– HEXIS employees and staff who require it to perform their duties and manage our relationship with you (depending on the category of data and level of responsibility);
– HEXIS CM's service providers and subcontractors, for the purposes of providing services;
– Lawyers, court officers, and ministerial officers, as well as administrative or judicial authorities involved in a dispute, where applicable, in compliance with HEXIS's legal obligations or to enable HEXIS to defend its rights and interests;
– departments responsible for oversight, such as auditors and internal control departments.
Your other personal data will not be shared with third parties without your prior consent.
If HEXIS becomes aware that a third party is using or disclosing personal data in violation of this Privacy Policy or in violation of applicable law, HEXIS will take all reasonable measures to prevent or terminate such use or disclosure.
In the event of a personal data breach being detected, HEXIS, as data controller, will inform the Data Protection Officer and the CNIL (French Data Protection Authority), the competent national supervisory authority, in accordance with applicable regulations, and, where applicable, the data subjects.
4- How long is your personal data retained?
The retention period for your personal data may vary depending on the purpose for which it was collected.
Legal obligations may require retention for a minimum period. In other cases, your data will only be retained for the purpose of fulfilling the intended purpose, or in compliance with applicable regulations. When it is no longer retained, your personal data will be destroyed.
Information stored on your device (e.g., cookies) or any other element used to identify you and allow for traceability, as well as raw traffic data associated with an identifier, will not be retained for longer than twelve months.
5- Is your personal data transferred abroad?
The personal data collected and processed by HEXIS is hosted in the European Union.
However, your data may be transferred to service providers and subcontractors located in countries outside the European Union, such as the United States.
To ensure respect for your privacy and personal data, HEXIS will ensure that the relevant business partners and subcontractors are signatories to the standard contractual clauses established by the European Commission.
6- What are your rights and how can you exercise them?
HEXIS has implemented appropriate personal data protection measures to ensure that personal data is used in accordance with the purposes described.
above and to ensure their accuracy and updating.
You therefore have the right to obtain disclosure of your personal data and, where applicable, to request the rectification, updating, portability, or deletion of personal data that is inaccurate, incomplete, ambiguous, outdated, or whose collection, use, disclosure, or retention is prohibited. You also have the right to request the restriction of the processing of your personal data or to object to such processing for legitimate reasons.
You may exercise your rights of access, rectification, or erasure by sending a letter by post or email, along with a copy of your identity card, to our company's Data Protection Officer at the following address:
Postal address:
HEXIS
Attn: Data Protection Officer
Z.I. Horizon Sud
CS 970003
34118 FRONTIGNAN CEDEX
Email address: rgpd@hexisgroup.com
For your information, you may contact the French Data Protection Authority (CNIL) (contact details are available at https://www.cnil.fr/fr/vous-souhaitez-contacter-la-cnil) if HEXIS has not responded to your request.
7- Security of your data
HEXIS strives to protect and secure the personal data you choose to share with us, ensuring its confidentiality and preventing it from being distorted, damaged, destroyed, or disclosed to unauthorized third parties.
HEXIS has taken physical, electronic, and organizational safeguards to prevent any loss, misuse, unauthorized access or disclosure, alteration, or destruction of this personal data. However, despite HEXIS's efforts to protect your personal data, HEXIS cannot guarantee the infallibility of these security measures due to unavoidable risks that may arise during the transmission of personal data.
8- Cookies
HEXIS reserves the right to use cookies or similar systems on its Website to facilitate navigation on the Website, personalize and improve the information displayed on it, monitor its use, and for statistical and security purposes (including: IP address, type of Internet browser and operating system used, and/or the pages of the Website visited).
For more information on the processing of cookies, including how you can manage the installation of these cookies, we invite you to consult the "Cookie Management Policy" section on our Website.
9- Dispute Resolution
Although HEXIS has taken reasonable measures to protect personal data, no transmission or storage technology is completely infallible.
However, HEXIS is committed to ensuring the protection of personal data. If you have reason to believe that the security of your personal data has been compromised or misused, you are invited to contact the Data Controller at the following address:
HEXIS
Attn: Data Controller
Z.I. Horizon Sud
CS 970003
34118 FRONTIGNAN CEDEX
HEXIS will investigate complaints regarding the use and disclosure of personal data and attempt to resolve them in accordance with the principles set out in this Privacy Policy.
10- How to contact HEXIS regarding the protection of your personal data?
For any questions regarding this Personal Data Protection Policy, you can send a letter to the following address:
Postal address:
HEXIS
Attn: Data Protection Officer
Z.I. Horizon Sud
CS 970003
34118 FRONTIGNAN CEDEX
Email address: rgpd@hexisgroup.com
If you are not satisfied with the answers provided, you have the right to contact the French National Commission for Information Technology and Civil Liberties (CNIL) directly (more information at www.cnil.fr).
11- Revision of the Privacy Policy
This Privacy Policy may be updated according to HEXIS's needs and circumstances, or if required by law.
Any changes will be notified via the HEXIS website or by email, whenever possible, at least thirty days before they come into effect.
This Privacy Policy is available upon request from the Data Protection Officer, whose contact details are mentioned above.