I. Responsible position and data protection officer

The one responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions:

Expleo Group’s Headquarters : 3 avenue des Prés, 78180 Montigny-le-Bretonneux, France

Tel: +33 1 30 12 25 00 

Publication Director: M. Rajesh Krishnamurthy

The data protection officer of the responsible person can be contacted at dpo@expleogroup.com

II. Protection of your personal data

Data protection is very important to us. Accordingly, we process personal data only in accordance with the legal provisions for data protection and data security. Our employees are committed by us to confidentiality and secrecy. Our online offer is accessible without registration, i.e. without providing your personal data and can in principle be used without disclosing your identity or manually entering personal data. If you would like to order products or services or to obtain information, we ask for your personal information. The extent to which we process personal data is described in detail below.  

III. General information regarding the processing of personal data

1. Description of the processing of personal data

We use IT systems on our websites for the provision of services to our customers, for which we process the personal data described in more detail below.

2. Legal basis for the processing of personal data

As far as we can we obtain the consent of the data subject for the processing of personal data, Art. 6 para. 1 lit. a GDPR serves as legal basis. In the processing of personal data necessary for the performance of a pre-contractual and/or contract obligations to which the data subject is a party, Art. 6 para. 1 lit. b GDPR serves as legal basis. As part of pre-contractual and/or contractual obligations, we may process your personal data for:

  • answering any requests, queries or inquires you may submit on our website; but also
  • enabling you log on certain restricted parts of our website;
  • managing your participation to online context

We may also use the personal data you share with us, for:

  • maintaining and improving the website as well as to ensuring its security;
  • conducting customer satisfaction surveys;
  • manage the forums to which you may take part;
  • recruitment purposes related when you submit a resume or a job application online; and
  • compiling aggregate statistics regarding the use of the website.

These purposes are justified by our legitimate interest to make sure that you enjoy the experience when visiting our website and interacting with us. Finally, subject to your prior express consent, we may also use the personal data you share with us for marketing purposes and in particular to provide you with personalised offers. If processing of personal data is required to fulfill a legal obligation that is subject to our company, Art. 6 para. 1 lit. c GDPR serves as legal basis. If processing is necessary to safeguard the legitimate interests of our company or a third party, and if the interests, fundamental rights and freedoms of the data subject do not prevail over the first interest, Art. 6 para. 1 lit. f GDPR serves as legal basis for processing.

3 Disclosure and sharing your personal data

3.1 With other entities of the group

Expleo Group  is a global organisation. Whilst we have distinct legal entities of the group (e.g., country subsidiaries) in many parts of the world, our internal processes and infrastructure are international in scope and nature and generally cross-country borders. Accordingly, you should be aware that we may share your personal data with other entities of Expleo Group and transfer it to countries in the world where we have data centres or otherwise do business, including those located outside the European Union (EU). Such data transfers will benefit from the same level of protection. For the purposes set out below, entities of the group or entities of Expleo means any company within Expleo Group which is controlled directly or indirectly by Expleo Group S.A.S.

3.2 Third-party suppliers

We also rely on third-party suppliers and partners with which we may share your personal data for the purposes indicated above except for marketing purposes. Whenever we rely on such third parties, we make sure that they provide an adequate level of protection to the personal data they process on our behalf and when such third parties are located out of the European Union, we make sure that we enter into European Model Clauses as adopted by the European Commission. You can obtain a copy of the said EU Model Clauses by clicking here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/model-contracts-transfer-personal-data-third-countries_en

3.3 Judicial, public and/or governmental authorities

We may also be required – by law, legal process, litigation, and/or requests from public and governmental authorities within or outside your country of residence— to disclose your personal data.  We may also disclose your personal data if we determine that for purposes of national security, law enforcement, or other issues of public importance, disclosure is necessary or appropriate. We may also disclose personal information if we determine in good faith that disclosure is reasonably necessary to protect our rights and pursue available remedies, enforce our terms and conditions, investigate fraud, or protect our operations or users.

4. Data deletion and storage duration

The personal data of the data subject will be deleted or blocked as soon as the purpose of the storage is invalidated. It may also be stored if provided for the European or national legislature in regulations, laws or other regulations to which the controller is subject. The data is therefore deleted or blocked if a storage period prescribed by the standards mentioned expires, unless the storage of the data is necessary for a fulfillment of the contract or an overriding legitimate interest.

5. Business reorganisations

Like many organisations, Expleo Group may reorganise its business operations around the world from time to time, whether by buying new businesses or selling or merging existing businesses. This may involve us disclosing personal data to prospective or actual purchasers of parts of our business, or receiving personal data from potential sellers. It is our practice to seek appropriate confidentiality protection for personal data disclosed in these types of transactions.  

IV. Calling our website

1. Description and scope of data processing

When you visit our website www.expleo.com, the browser used on your device automatically sends information to the server of our website. This information is temporarily stored in a log file. The following information will be collected without your intervention and stored until automated deletion:

  • IP address of the requesting computer
  • Date and time of access
  • Name and URL of the retrieved file
  • Website from which access takes place (referrer URL)
  • The browser used and, if applicable, the operating system of your computer

The log files contain IP addresses or other data that allow an assignment to a user.

2. Purpose of data processing

The temporary storage of the IP address by the system is necessary to allow delivery of the website to the computer of the user. To do this, the user’s IP address must be kept for the duration of the session. Storage in log files is done to ensure the functionality of the website. In addition, the data is used to optimize the website and to ensure the security of our information technology systems. An evaluation of the data for marketing purposes does not take place in this specific context. In particular, we use the data:

  • To ensure a smooth connection of the website
  • To ensure comfortable use of our website
  • For evaluations of system security and stability
  • For further administrative purposes

In addition, we use cookies and analysis services when visiting our website. Further details can be found under no. VI of this Privacy Policy.

3. Legal basis of data processing

The legal basis for data processing is Art. 6 para. 1 p. 1 lit. f GDPR. Our legitimate interest follows from the data collection purposes described above. In this specific context, we do not use the data collected for the purpose of drawing conclusions about you.

4. Duration of storage

The data will be deleted as soon as it is no longer necessary for the purpose of its collection. In the case of the collection of data for the provision of the website, this is basically the case when the respective session is completed. As far as complete storage of IP addresses takes place in log files, the personal data will be deleted or anonymized after (7) seven days at the latest. Any further storage is possible in connection with cookies or analysis services. In this case, the IP addresses of the users are deleted or shortened, so that a mapping of the calling client is not possible. Further details can be found under no. VI of this Privacy Policy.

5. Contradiction and elimination possibility

The collection of data for the provision of the website and the storage of the data in log files are essential for the operation of the website. There is consequently no contradiction on the part of the user.  

V. Forms on the website, newsletters, information

1. Description and scope of data processing

All personal data collected in connection with forms on our website are voluntarily provided by the user.

Contact form

We use a form on our website where you can contact us. We collect the following personal data: name, address, e-mail address, company, industry, position, telephone number, country, your message to us.

Order form

Our training website contains order forms that you can fill out to request information, products or services. We collect the following personal data: number of participants, name, company, job title, e-mail address, telephone, postal address, text of the message.

Newsletter

 Assuming you have a separate agreement, we will also use the personal data stored by us to inform you about our products, services and events. On the website a form for the registration to our newsletter is provided, through which we collect the necessary personal data (name, e-mail address). We will only send you information by electronic means if you have expressly given your consent in writing or in the Double-Opt-In procedure.

Webinar with GoToWebinar

 A webinar is comparable to a presence seminar and takes place computer- and software-supported over the internet. You can join a webinar if you have previously logged in through our webinar page. The following data is requested: name, e-mail address, company, position, telephone. To run webinars over the Internet, Expleo uses the GoToWebinar software solution from LogMeIn, Inc. LogMeIn, Inc. is the controller of this service and associated data processing. The privacy policy of LogMeIncan be found here. For the order-related execution of the webinar, we will submit your login or customer information to LogMeIn, Inc.

During and after the webinar, statistics are transmitted to Expleo. If you participate in a webinar, ask or answer a question during the webinar, in addition to your credentials we will receive information about the duration of the course, interest in the webinar, the question asked, or answer to further customer support or to enhance the user experience. Optionally, you can edit documents and forms together with your contact person. An encrypted connection is established between you and the organizer of the webinar. The audio or video information transmitted during this session will not be recorded by us. By clicking on “Join” you confirm that you too will not be recording or making a screenshot of this session. You can end the session at any time by simply closing the browser window or exiting the program or app. If your contact person terminates the session, your session participation will be automatically terminated.

2. Purpose of data processing

We process the personal data in order to process your inquiries, to provide you with the services you require, to issue invoices, to ensure compliance with laws and regulations, and to enforce legal claims.

3. Legal basis of data processing

The legal basis for data processing is Art. 6 para. 1 p. 1 lit. a and b GDPR, as each of you consent to the use of a form, a Webinar or to the provision of information and a contractual service is provided.

4. Duration of storage

The personal data collected will be stored for as long as necessary for the purposes described.. As far as the data are subject to legal storage obligations under local legal requirements, they must be kept for six or ten years. Incidentally, the general storage principles described above apply.

5. Contradiction and elimination possibility

As far as the data is subject to legal storage obligations according to legal requirements, the user has no right of objection. You may revoke your consent to sending the newsletter or information at any time, either via the unsubscribe link in the individual submissions, or informally at info@expleogroup.com. In all other respects, the rights of the persons concerned described below exist;  

VI. Cookies, plugins and web analysis

1. Description and scope of data processing

What are cookies?

When requesting content from our online offering, cookies are set for example to optimise communication times or for the anonymous, statistical evaluation of the use of our website. Cookies are small text files that are stored on the user’s computer when visiting a website. They can be automatically recognized and read during a current or next visit. If you leave our site and access third pages, the landing page may also set cookies. We are not legally responsible for the cookies. For the use of these cookies by third parties and the information stored therein, please compare the local privacy statements and the following statements.

What data is processed?

Cookies, analysis tools and plug-ins are used, among other things. the name of the Internet service provider, requested files, IP address, access to individual pages, browser type, screen resolution, color depth, operating system, search terms and reference pages from which you have accessed our web pages. In the following, we also describe in detail which cookies, analysis tools and plug-ins we use, which data is processed and how you can deactivate the analysis tools.

Google (Universal) Analytics

The website uses Google Analytics, a web analytics service provided by Google Inc. (https://www.google.de/intl/de/about/, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA, hereafter “Google”). In this context, pseudonymised usage profiles are created and cookies are used. The information generated by cookies about your use of this website such as:

  • Browser type / version,
  • Used operating system,
  • Referrer URL (the previously visited page),
  • Host name of the accessing computer (IP address),
  • Time of server request,

are transmitted to a Google server in the US and stored there. The information is used to evaluate the use of the website, to compile reports on website activity and to provide other services related to website activity and internet usage for the purposes of market research and customization of these websites. This information may also be transferred to third parties if required by law or if third parties process this data in the order. By activating the IP anonymization on this website, the IP address will be shortened before transmission within the EU or the EEA (IP masking). Only in exceptional cases will the full IP address be sent to a Google server in the US and shortened there. The anonymized IP address provided by Google Analytics within the framework of Google Analytics will generally not be merged with other data provided by Google.

You can prevent the installation of cookies by setting the browser software accordingly (see below). We point out, however, that in this case not all features of this website may be fully exploited. In addition, you can prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) and the processing of this data by Google by downloading and installing a browser add-on ( https://tools.google.com/dlpage/gaoptout?hl=de ).

As an alternative to the browser add-on, especially for browsers on mobile devices, you can prevent the collection by Google Analytics by clicking on this Link. An opt-out cookie will be set which prevents the future collection of your data when visiting this website. The opt-out cookie is only valid in this browser and only for our website and is stored on your device. If you delete the cookies in this browser, you must set the opt-out cookie again. Google is headquartered in the US and is certified under the EU-US Privacy Shield. A current certificate can be viewed here

Under the agreement between the US and the European Commission, the latter has established an appropriate level of data protection for companies certified under the Privacy Shield. For more information about privacy related to Google Analytics, see the Google Analytics Help Center ( https://support.google.com/analytics/answer/6004245?hl=en )

Remarketing function of Google

This website uses the remarketing feature of Google Inc. (“Google”). This feature is designed to show interest-based ads to visitors to the site through the Google Network. The website visitor’s browser stores so-called “cookies”, text files that are stored on your computer and that make it possible to recognize the visitor when he or she visits websites that belong to the Google advertising network. On these pages, visitors can then be presented with ads that relate to content that the visitor previously viewed on web pages that use Google’s remarketing feature. Google says it does not collect any personal information during this process. If you do not wish to use the Google Remarketing feature, you can disable it by making the appropriate settings at http://www.google.com/settings/ads. For more information about Google Remarketing and the Google Privacy Policy, please visit: http://www.google.com/privacy/ads/

Retargeting Cookies exclusively on expleo.com

We use third-party providers who advertise for us on the Internet. These third parties will identify your IP address and collect information about your visit to our website, which may also result in our advertisements being displayed when you visit other websites. This information is collected by means of a pixel tag (also called cookie and action tag). The information is not personal to us because it does not include your name, address, email address or other personal information. However, it may trace your IP address, which is widely considered a personal date.

2. Purpose of data processing

We process and use the resulting data to improve the marketing of our websites, to increase the user-friendliness of the websites and for other optimisation purposes. The analysis required for marketing and optimisation purposes usually does not allow us to identify your personal or personal information. In particular, no names, addresses, telephone numbers or other data are stored that can be directly attributed to individuals. The analysis provides only aggregated data, such as the number of visitors and the page views. We point out, however, that according to widespread opinion, dynamic IP addresses and the associated usage data are classified as personal data. Among other things, cookies allow us to tailor our website to your wishes, to establish connections between different visits to our website, or to store your password in the browser so that you do not have to reenter it every time. We also use cookies for target group advertising. We also allow data providers or other automatic data collection tools to use our cookies to help us deliver our own content and advertisements as well as measure the effectiveness of our advertising efforts. These cookies may provide anonymous or other data, linked to data that you have transmitted to us and that we pass on to data providers in hashed form, that is unreadable by humans. For registered users, the data collected on our websites is not anonymous. We use this information together with other information that we know or derive about you, such as: For example, your preferences to provide content, services, and advertisements tailored to you. We do not pass on any information to these advertisers and other third parties that directly identifies you. Advertisers and other third parties (such as ad networks, ad agencies, and any other service providers they may mandate) can only assume that users who interact with or click on personalized ads or content belong to the audience to which the ad or content relates directed.

3. Legal basis of data processing

The illustrated cookies, plugins and tracking measures are based on Art. 6 para. 1 p. 1 lit. f GDPR. The data processed thereby for the named purposes serves the preservation in the context of a weighing of interests over predominant legitimate interests of our enterprise and third, in particular on a promotional approach of our customers, and are therefore necessary according to the proportionality principle.

4. Duration of storage

Some of the cookies we use are deleted after the browser session ends, ie after closing your browser (so-called session cookies). Other cookies remain on your device and allow us to recognize your browser on your next visit (persistent cookies). The duration of the storage can be found in the overview in the cookie settings of your web browser. Incidentally, the general storage principles described above apply.

5. Contradiction and elimination possibility

If you do not want us to use cookies, set your Internet browser to erase cookies from your hard drive, block all cookies, or warn you before a cookie is stored, so you can decide on a case-by-case basis whether you want the cookie. Each browser differs in the way it manages the cookie settings. They are described in detail in the help menu of each browser. It explains how to change your cookie settings. You will find the respective browser information, e.g. under the following links:

5.1 Internet Explorer:

5.2 Firefox:

5.3 Safari:

5.4 Chrome:

5.5 Opera:

https://help.opera.com/en/latest/security-and-privacy/

Important: Certain features, such as content recovery, can only be used through the use of cookies. We therefore recommend that you do not completely disable cookies. Incidentally, you will also find the options for deactivation in each case directly in the description of cookies, plugins and tracking measures (see above).

VII. Rights of the concerned person

Due to the privacy policy you have the following different rights.

1. Right of inquiry

You have the right to request information about your personal data processed by us in accordance with Art. 15 GDPR. In particular, you can provide information on the purposes of processing, the category of personal data, the categories of Recipients against whom your data has been or will be disclosed, the planned storage period, the right to rectification, deletion, limitation of processing or opposition, the existence of a right to complain, the origin of their data, if they were not collected from us, as well as require the existence of automated decision-making including profiling and, where appropriate, meaningful information about their details.

2. Right of correction

In accordance with Art. 16 GDPR, you have the right to demand the correction of incorrect or incomplete personal data stored by us.

3. Right of deletion

You have the right, in accordance with Art. 17 GDPR, to request the deletion of your personal data stored by us, unless the processing for the exercise of the right to freedom of expression and information, for the fulfillment of a legal obligation, for reasons of the public interest or for assertion, Exercise or defense of legal rights is required.

4. Right of restriction of processing

You have the right, according to Art. 18 GDPR, to restrict the processing of your personal data, if the accuracy of the data is disputed by you, the processing is unlawful, but you reject its deletion, we no longer need the data, but you they are required to assert, exercise or defend legal claims or you have objected to the processing pursuant to Art. 21 GDPR.

5. Right of data portability

You have the right, in accordance with Art. 20 GDPR, to receive your personal data provided to us in a structured, standard and machine-readable format or to request the transfer to another person in charge.

6. Right to revoke the data protection consent declaration

In accordance with Art. 7 (3) GDPR, you have the right to revoke your data protection consent declaration at any time. As a result, we may no longer continue the data processing based on this consent. The revocation of consent does not affect the legality of the processing carried out on the basis of the consent until the revocation. If you want to make use of your right of revocation, it is sufficient to provide a corresponding notification via all known means of communication, in particular also by e-mail info@expleogroup.com

7. Right to complain to a supervisory authority

You have the right to complain to a supervisory authority in accordance with Art. 77 GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or work or our company headquarters.

8. Right to contradict

If your personal data is based on legitimate interests in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR are processed, you have the right to file an objection against the processing of your personal data in accordance with Art. 21 GDPR, provided that there are reasons for this arising from your particular situation or that you have an opposition directed against direct mail. In the latter case, you have a general right of objection, which is implemented by us without specifying any particular situation. If you would like to make use of your right to object, a corresponding notification via all known communication channels, in particular also by e-mail, is sufficient to info@expleogroup.com. After exercising your right to object, we will not further process your personal data for these purposes, unless we can demonstrate compelling legitimate grounds for processing that outweigh your interests, rights and freedoms, or if the processing of the assertion, exercise or defense of Legal claims serves. This does not apply if the processing is for direct marketing purposes. Then we will not process your personal data for this purpose.

9. Automated decision on an individual basis including profiling

You have the right not to be subjected to a decision based solely on automated processing – including profiling – that will have legal effect or affect you in a similar manner. This does not apply if the decision

  1. Is required for the conclusion or performance of a contract between you and the controller,
  2. Is permitted by Union or Member State legislation to which the controller is subject, and where such legislation contains appropriate measures to safeguard your rights and freedoms and legitimate interests, or
  3. With your express consent.

However, these decisions must not be based on special categories of personal data under Art. 9 (1) GDPR, unless Art. 9 (2) lit. a or g GDPR applies and reasonable measures have been taken to protect the rights and freedoms as well as your legitimate interests. With regard to the cases referred to in (1) and (3), the controller shall take appropriate measures to safeguard your rights and freedoms and legitimate interests, including at least the right to obtain the intervention of a person by the controller, to express his / her own position and Contesting the decision is one.

VIII. Data security

When visiting our websites, we use the widely used SSL (Secure Socket Layer) method in combination with the highest encryption level supported by your browser. Whether an individual page of our website is transmitted in encrypted form can be recognized by the fact that the address line of the browser changes from “http: //” to “https: //” and to the closed representation of the key or lock symbol in the browser line. We also take appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or total loss, destruction or against unauthorized access by third parties. Our security measures are continuously improved in line with technological developments. The security measures described are based on Art. 6 para. 1 sentence 1 lit. f, Art. 32 GDPR. The data processed thereby is used for security purposes to safeguard our legitimate interests and the interests of third parties pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR required.

IX. Actuality and change of this data protection statement

This privacy policy is currently valid and has the status of February 2019. Due to the further development of our website and offers or due to changed legal or regulatory requirements, it may be necessary to change this privacy policy. The current privacy policy is available at any time on our website and can be viewed and printed by you.