KeoLife Week confidentiality policy
Version of 1 May 2019

The company Keolis S.A. ("Keolis S.A. " or "We") does everything possible to protect your personal data in accordance with applicable European and French regulations.

This Confidentiality Policy ("Confidentiality Policy") is intended to inform you of the purposes and conditions under which we process any personal data we may collect through the KeoLife Week platform available at the following link https://keolife.keolis.com hereinafter "the Platform").

Our Cookies Policy, available on the platform at the following link https://keolife.keolis.com/p/cookie-policy this Confidentiality Policy to inform you of the purposes and conditions of use of cookie files or browsing data that may be deployed by Keolis S.A. We invite you to carefully read this Confidentiality Policy to ensure you have all the information you need to understand the use of your personal data and to freely and fully assert the rights guaranteed to you by applicable laws and by this Confidentiality Policy.

1 - General provisions

Data Controller

The data controller for your personal data is the company Keolis S.A.

General Terms and conditions

The Confidentiality Policy is an integral part of the General Terms and Conditions of our Platform and must be read in conjunction with them (which are accessible via this link https://keolife.keolis.com/p/terms-of-service

Applicable law and competent administrative authority

The Confidentiality Policy is governed by General Data Protection Regulation No. 2016/679 ("GDPR") and the amended Data Protection Act No. 78-17 of 6 January 1978 as amended ("Data Protection Act"), under the regulatory control of the French authority for the protection of personal data, the CNIL (National Data Protection Commission – www.cnil.fr).

2. The personal data we collect

The Confidentiality Policy applies to personal data that we may collect from you or concerning you (see below), from the following sources:

  • When browsing the Platform (especially when using a feature or consulting resources available on the site);
  • To access the Platform and during its use, and when receiving and sending emails, text messages and other electronic messages between Keolis S.A. and you. The following data is collected:
  • Name, first name, email, password used to access and manage your account,
  • Photographs (and authors' names) uploaded to the Platform and taken during Keolife Week,
  • Technical cookies and audience measurements,
  • Connection, download, and IP address logs,
  • The nature of the request and the identity card in the framework of asserting a right.

3. Legal basis of processing

The processing carried out by Keolis is based on:

  • consent: creation and management of the account to access the platform, and management of the Platform and audience measurement cookies.
  • legitimate interest: the management of requests to assert rights, statistical analysis, technical cookies, connection and download logs.

4. Use of your personal data

We collect and use personal data concerning you for the main purposes described below:

  • Management of KeoLife Week events,
  • The management of photographs taken at Keolife Week,
  • To create your account and manage the access and use of the Platform and the provision of the resources present;
  • To carry out statistical analyses; comply with the law, regulations and lawful requests and orders.

5. Data transmission

Your personal data may be disclosed by Keolis S.A.

Within Keolis SA

To the administrators of the Platform, and the information systems Department. Audience measurement statistics may be shared with other members of the Keolis Group.

To providers

We may disclose your personal data to trusted third parties, providers of Keolis SA, located within the European Union, to ensure the proper functioning of the platform (publisher and integrator of the Platform) and the hosting of data (server in France).

To third parties on legal grounds

Where we are required to comply with laws and regulations and lawful requests and orders, or if permitted by law (that is to say for the protection and defence of rights, a situation which is threatening to life, health or safety, etc.).

***

In any event, we always require these recipients to submit guarantees of confidentiality and sufficient security and to take the physical, organisational and technical measures necessary to protect and secure your personal data, pursuant to current law.

6. Data security

Keolis S.A. secures your personal data by putting adequate physical, organisational and technical measures in place to prevent unauthorised access, use, disclosure, modification or destruction, pursuant to regulations in force.

These measures include:

  • Storage on secure servers within the European Union;
  • Securing your data, in particular using pseudonymisation processes, encryption of the data transmitted and the implementation of means to ensure the confidentiality, integrity and availability of your data;
  • Limited access to your data based on a "need to know".

Although Keolis S.A. takes all possible measures to protect your personal data, we cannot guarantee the security of information disclosed on our website when a security breach affects your device or browser.

7. Your rights to your personal data

Under the GDPR and the Data Protection Act, you have various rights including:

Access, modification, update and erasure of your personal data

You may request access to your personal data held and processed by Keolis S.A., consult it, obtain a hard or electronic copy thereof and request its correction, updating or erasure.

Right to withdraw your consent

In respect of processing based on the collection of your consent, you may withdraw it at any time.

Objection

You may request that some of your data be no longer processed at any time, when this is applicable.

Portability

You may request that your processed data is made available to you in an open and machine-readable format for your personal use or to be passed on to another data controller when this is applicable.

Limitation of processing

In certain cases, you may request that the processing of your data be limited.

Complaint to a Supervisory Authority

Without prejudice to any other legal process, you have the right to file a complaint with the supervisory authority of the European Union country in which you reside, work or in which you consider that a breach of your rights has been committed.

***

You may exercise all these rights by sending a written request, accompanied by a copy of your ID, to the addresses mentioned in Article 9 "Contact Us".

We will seek to respond to your request as soon as possible and under the conditions provided by applicable regulations. Nevertheless, in some cases, we may not be able to grant your request, in order to meet our legal or contractual obligations.

8. Retention periods for collected data

We keep your personal data only for the time necessary to fulfil the different purposes defined in Article 3 "Use of your personal data" above, except where the law allows us or requires to keep it for longer.

The table below summarises the different maximum retention periods applicable or binding on Keolis S.A. depending on the purposes for which your personal data may be processed. These maximum terms apply unless you request the erasure or termination of use of your data before the expiry thereof for a reason consistent with any legal obligation that may be binding on Keolis S.A. Regarding your account, the erasure of your data may occur prior to the date indicated below, in accordance with the duration of the access you have been authorised to have by Keolis S.A.

Purposes Retention periods
Creating and managing your account Data collected for the creation of your account, and the accounts created, will be deleted one month after the end of KeoLife Week
The management of photographs taken at Keolife Week 5 years from the end of Keolife Week
cookies 13 months after the storing of the cookie, cf. the cookies policy
Connection, IP address logs 1 month after the end of KeoLife Week
Management of rights requests 5 years from the receipt of the request

9. Modification of the Confidentiality Policy

Keolis S.A. reserves the right to make changes to the Confidentiality Policy.

We encourage you to regularly check this page for updates and to keep informed about what we are doing to protect your personal information.

10. Contact us

To assert your rights or for any question relating to the processing of your personal data, please contact our Data Protection Officer at this email address: dpo@keolis.com or the postal address:

Keolis SA
Data Protection Officer
20 rue Le Peletier
75009 PARIS