Privacy Policy and Cookies
Preamble
We know you care about your personal data and how it is used. You can trust SMERRA to handle it with the utmost care. This Privacy Policy explains the types of personal data we collect, why we collect it, and how we use it. Please take the time to familiarize yourself with our privacy practices and feel free to contact us with any questions by sending us a message via this form.
Personal data: any information that can be used to directly or indirectly identify a specific individual.
Data processing: The processing of personal data refers to any operation or set of operations performed on personal data (collection, retrieval, adaptation, storage, etc.).
Data controller: The data controller is, in principle, the person, public authority, company, or organization that determines the purposes and means of processing the data and decides on its creation.
Purpose: The purpose of processing is the primary objective of using personal data. Data is collected for a specific and legitimate purpose and is not subsequently processed in a manner incompatible with that initial purpose
Processor: A processor, as defined by the GDPR, is a natural or legal person (company or public body) that processes data on behalf of another entity (the data controller) as part of a service or provision of services
Sensitive data: This refers to information revealing a person’s alleged racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation. The European Regulation prohibits the collection or use of such data, except, in particular, in the following cases:
• If the data subject has given their explicit consent (an active, explicit, and preferably written act, which must be freely given, specific, and informed);
• If the information has been clearly made public by the data subject;
• If it is necessary to protect human life;
• If its use is justified by the public interest and authorized by the CNIL;
• If it concerns members or affiliates of a political, religious, philosophical, or trade union association or organization.
Data breach: characterized by the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data transmitted, stored, or otherwise processed.
Identity and contact information of the data controller
When you visit our website, the UITSEM Group, as the data controller, may collect your personal data in connection with the performance of your insurance contracts.
All personal data provided to or collected by SMERRA is controlled by the UITSEM Group, 43 Rue Jaboulay, 69007 Lyon.
Why and how do we collect your personal data?
We may collect your data through various means:
- Data you provide directly to us
- Website
- Personal account
- Phone
- Data we collect automatically (cookies)
- Data we collect from other sources (marketing, partners)
You are not required to provide SMERRA with the personal data we request, but if you choose not to do so, we may not be able to provide you with our products and services, or a high-quality service, or respond to any requests. We collect only the data strictly necessary for the purpose of data processing.
| Data Processing and Purpose | Legal Basis | Catégorie de données | Recipient | Shelf life |
| Tenant Management: | Performance of a contract Legitimate interests pursued by the data controller |
Personal information: last name, first name, date and place of birth Professional life: Employment and workplace Personal life: Family situation Financial information: Income, bank account details, tax residence |
Employees and subcontractors authorized to process this information solely for the purpose of managing your contracts and services | 5 years from the end of the contract |
| Contact Request: • Form • Personal Account |
Consent Legal obligation (telephone recording) Performance of a contract |
Identification Information Phone Recording |
Internal staff authorized to manage them solely for the purpose of managing your contracts and services | 3 years from the end of the contract |
| Cookie Management | Consent | Connection data: IP addresses, logs, etc. Browsing data |
Internal staff | 13 months |
Cookie Policy
When you visit our website, cookies are sent to your computer, tablet, or mobile device. Our cookie policy helps you better protect yourself from cookies while understanding their purpose.
You can accept or decline cookies directly on our site by selecting your preference using the banner that appears at the bottom of your screen
What is a cookie?
A cookie is a text file that the website you visit stores on your hard drive or in your browser’s cache. It allows your computer to store various technical data, such as the number of visits, the frequency of exposure to an ad banner, and connections to other sites. It also helps personalize your future visits by remembering your site language preference, login information, and settings.
Why does our website use cookies?
Our website uses cookies to ensure it functions properly and to make your browsing experience easier.
– Technical and navigation cookies: These cookies facilitate your navigation between pages on our website and are necessary to allow you to use certain features, such as your user account. These cookies expire when you close your web browser.
– Audience measurement cookies: To measure our website’s audience, we collect information such as the amount of time you spend on our website, which buttons you clicked, and how you arrived at the website (referring sites, social media, search engines, etc.). Thanks to these cookies, we measure the effectiveness of our interactive content and improve our services
– Third-party cookies: These are cookies placed by third-party companies. Our site uses the FAZAE hosting provider, which automatically integrates some third-party cookies. These third-party companies collect cookies to power their ad targeting systems.
– Social media cookies: Cookies may also be used on sites that offer the ability to share our content, particularly social media sites. Cookies placed by social media sites are their sole responsibility. You can view the privacy policies for each of these sites at the following addresses:
• Facebook: https://www.facebook.com/about/privacy/
• Instagram: https://privacycenter.instagram.com/policy/
• YouTube and Google+: https://www.google.fr/intl/fr/policies/privacy/
• LinkedIn: https://www.linkedin.com/legal/privacy-policy
Cookie retention period
The cookies we collect are retained for a maximum of 13 months.
Essential
Essential cookies are crucial for the website’s basic functions, and the website will not work as intended without them.
These cookies do not store any personally identifiable information.
Functional
Functional cookies enable certain features, such as sharing website content on social media platforms, collecting comments, and other third-party features.
Analytics
Analytics cookies are used to understand how visitors interact with the website. These cookies help provide information on the number of visitors, bounce rate, traffic source, and more.
Advertising
Advertising cookies are used to provide visitors with personalized ads based on the pages they have previously visited and to analyze the effectiveness of the advertising campaign.
How do we protect your personal data?
The UITSEM Group takes the security of your personal data very seriously. We strive to protect your personal data against any data breaches, including misuse, interference, loss, unauthorized access, alteration, or disclosure.
Our measures include implementing appropriate access controls and investing in the latest information security capabilities to protect the IT environments we operate.
Access to your personal data is permitted only among our employees and agents on a need-to-know basis and is subject to strict contractual confidentiality obligations when the data is processed by third parties.
What are your rights?
In accordance with the amended French Data Protection Act of January 6, 1978, and European Regulation No. 2016/679/EU of April 27, 2016, you have the right to access your personal data, correct it, request its deletion, or exercise your right to data portability or to restrict the processing of your data. You may also withdraw your consent at any time. To exercise these rights or for any questions regarding the processing of your data in this system, you may contact our Data Protection Officer (DPO) electronically by following this link.
If, after contacting us, you believe that your data protection rights have not been respected, you may file a complaint with the French Data Protection Authority (CNIL) either via the following URL: https://www.cnil.fr/fr/plaintes, or via email at the following address: 3 place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07
You can opt out of having your browsing activity tracked on this website. This will protect your privacy, but it will also prevent the site owner from learning from your actions and creating a better experience for you and other users.
With whom do we share your personal data?
The UITSEM Group may share your personal information internally and with selected third parties. For example, we may share your personal information with third-party service providers, other third parties, partners, or as required by law.
• Third-party service providers: In order to fulfill your requests, respond to your inquiries, process your contracts, allow you to participate in contests, and provide you with other features, services, and materials on our sites, we share your personal data with third-party service providers who perform functions on our behalf. These are companies that: host or operate websites, process payments, analyze data, provide customer service, or offer postal or delivery services. They have access to the personal information necessary to perform their functions but may not use it for any other purpose. Furthermore, they must process this personal information in accordance with this Privacy Policy and in compliance with applicable data protection laws and regulations.
List of service providers: Sogecommerce
• Legal Disclosure. We may transfer and disclose your personal data to third parties
– To comply with a legal obligation;
– At the request of government authorities conducting an investigation;
– To verify or enforce our “Terms of Use” or other applicable policies
– To detect and protect against fraud, or any technical or security vulnerabilities;
– To respond to an emergency; to protect the rights, property, safety, or security of third parties, or visitors to UITSEM Group websites
International Data Transfers
The UITSEM Group shares personal data internally or with third parties for the purposes described in this Privacy Policy.
The UITSEM Group will only transfer personal data collected within the European Economic Area (EEA) to countries outside the EEA in situations such as:
• Following your instructions;
• Complying with a legal obligation;
• Working with our partners and advertisers who assist us in managing our group and services.
If we need to transfer personal data outside the EEA, the UITSEM Group will ensure that it is protected in the same manner as within the EEA. We will use one of the following safeguards:
• Transferring to a non-EEA country whose privacy laws guarantee an adequate level of protection for personal data, similar to that in an EEA country;
• Enter into a contract with the foreign third party requiring it to protect personal data according to the same standards as the EEA
• Transfer personal data to organizations that are part of specific agreements regarding cross-border data transfers with the European Union (e.g., the Privacy Shield is a framework that defines the privacy standards for data transferred from European Union countries to the United States).
How do we update this Privacy Policy?
Updates to this Privacy Policy may incorporate customer feedback and changes to our products and services. When we make changes to this statement, we update the “Last Updated” date at the top of this document. If the changes are significant, we will provide a more prominent notice (including, for certain services, an email notification of changes to the Privacy Policy). We will also archive previous versions of this Privacy Policy so that you can review them.
Processing of Telephone Calls
The information collected by UITSEM is processed exclusively by authorized internal personnel. The purpose of this processing is the continuous improvement of our services. This data will be retained for as long as necessary to fulfill this purpose. In accordance with the amended French Data Protection Act of January 6, 1978, and European Regulation No. 2016/679/EU of April 27, 2016, you may access your personal data, correct it, request its deletion, or exercise your right to data portability or to restrict the processing of your data. You may also withdraw your consent at any time. To exercise these rights or for any questions regarding the processing of your data in this context, you may contact our Data Protection Officer (DPO) electronically by following this link.
If, after contacting us, you believe that your data protection rights have not been respected, you may file a complaint with the French Data Protection Authority (CNIL) either via the following URL: Online Complaints | CNIL, or via email at the following address: 3 place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07.