Privacy Policy

BAULDERS PRIVACY POLICY

This policy is the privacy policy of BAULDERS, a collaborative platform dedicated to project auditing, published by DIGIFIELD TECHNOLOGIES, a SAAS, with a capital of 217,353 euros, headquartered at 47 rue Marcel Dassault 92100 Boulogne-Billancourt, registered with the RCS of Nanterre under the following number: KBis 853 443 935.

Definitions

BAULDERS: The website of the company DIGIFIELD TECHNOLOGIES accessible at the address: https://baulders.com

Client: Any professional, natural person or legal person, who visits the Site Baulders.


Services: Baulders makes available to its Clients various services described in the Terms & Conditions of Use page available at https://baulders.com/terms/

Content: All the constituent elements of the information present on the Site, in particular texts – images – videos.

Customer information: Hereinafter referred to as “Information(s)” which correspond to all personal data that may be held by Baulders for the management of your account, customer relationship management and for analytical purposes, statistics.

User: Internet user visiting Baulders’s website.

Personal information: “Information that allows, in any form whatsoever, directly or indirectly, the identification of natural persons to which they apply” (Article 4 of French Law No. 78-17 of 6 January 1978 in its version prior to the 7th of August, 2004).

The terms “personal data”, “data subject”, “subcontractor” and “sensitive data” have the meaning as defined by the General Data Protection Regulation (GDPR: No. 2016-679)

1. Introduction

In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“GDPR”), BAULDERS, in its capacity as data controller, ensures the protection of users’ information. We ensure that individuals’ right to privacy is respected, when collecting and processing personal data, in the context of our online services. 

This privacy policy describes our practices regarding the processing of such personal data.

BAULDERS will only collect and process information received as described in this policy. By using our online services, you acknowledge that you have read this statement and expressly consent to the collection, use and disclosure of your personal information in accordance with this privacy policy. 

This document is subject to change, in particular to comply with the requirements of legislation on the protection of personal data. We strongly recommend that you consult this page regularly.

1.1 Contacts

For any request relating to this privacy policy, you are invited to contact the DPO, at DPO BAULDERS , DIGIFIELD TECHNOLOGIES SAS, 47,RUE MARCEL DASSAULT 92100 BOULOGNE-BILLANCOURT by sending your request to the following address dpo@baulders.com  or by telephone: +33 (0)143299317

 

2. Collection and processing of personal data

2.1 Compliance with data protection principles

BAULDERS undertakes that personal data will be:

– processed lawfully, fairly and transparently

– collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes.

– adequate, relevant and limited to what is necessary for the purposes for which the data is processed

– accurate and, if necessary, kept up to date

– kept in a form which permits identification of the data subjects for no longer than is necessary for the purposes for which they are processed.

– processed in such a way as to guarantee appropriate security of personal data.

2.2 Type of personal data collected

We collect the following information from users of the BAULDERS site, which is essential for the proper functioning of our services: surname, first name, e-mail address, address, phone number, etc.

We also collect information that is likely to improve the user experience, and that enables us to provide personalized advice: phone number.

2.3 Purpose of personal data collection

BAULDERS collects personal data in order to:

– enable optimal browsing of the BAULDERS website.

– optimize the technical management of the site, its management, and the traceability of its services, as well as services ordered by the user: connection and use of the site, invoicing, order history, etc.

– prevent and combat computer fraud (hacking, spam, etc.): hardware used for browsing, IP address, password hash, etc.

– improve site navigation: connection and use of data.

– conduct optional satisfaction surveys on BAULDERS: e-mail.

– to carry out communication campaigns (sms, e-mail): telephone number, e-mail.

For processing to be lawful, in accordance with Article 6 of the GDPR, BAULDERS verifies that at least one of the following conditions applies:

– the user concerned has given his/her consent to the processing of his/her personal data with regard to one or more purposes. 

– the processing of personal data is necessary for the performance of a contract to which the user is a party. This contract may be terminated at any time via the link allowing to Unsubscribe to the service and cancel account.

– data processing is necessary for the execution of pre-contractual measures requested by the user concerned. 

– processing is necessary to comply with a legal obligation to which BAULDERS is subject.

2.4 Recipients of personal data

BAULDERS does not sell or rent personal data which is strictly collected for purposes of necessity, or for statistical or analytical purposes. BAULDERS is however likely to share them with trusted partners, themselves subject to the requirements imposed by the GDPR in terms of data security and confidentiality. 

BAULDERS is likely to share personal data in the context of an express request from public authorities or any legal request in compliance with applicable laws. In such cases, BAULDERS takes all necessary measures to ensure that only strictly necessary information is communicated.

2.5 Retention period for personal data

The data communicated by the user necessary for the operation of BAULDERS services will be kept for a maximum period of 12 months from the end of the contractual relationship. 

At the express request of the Customer, data may be requested to be deleted immediately, at any time. In this case, BAULDERS undertakes to delete the data within a reasonable period of time in accordance with current regulations.

Data provided when the user uses the platform or connects to it is recorded for traceability and data security purposes, and will be kept for a maximum of one year.

BAULDERS may keep data relating to commercial management and canvassing for a period of 10 years from the last contact with the prospect.  

2.6 Data security

BAULDERS guarantees the security, integrity, authenticity and confidentiality of personal data by implementing technical and organizational measures. BAULDERS uses networks protected by firewalls, pseudonymization, encryption and passwords. These same measures also apply to the transfer and reception of data with our third parties.

The security measures implemented by the BAULDERS site are designed to prevent the loss, misuse and alteration of data. These include data backup, installation of anti-virus and other protection software, user access control, password hashing, etc. 

On the standard Baulders.com service:

Website data is stored on servers managed by: the company CLOUDWAYS

Application data is stored on servers managed by Google Cloud France SARL, according to the terms described on the https://cloud.google.com/terms website, with hosting specified in France under the https://cloud.google.com/terms/services data localization facility.

Administrative management of Baulders.com ERP support is managed under an Enterprise Subscription Agreement with Odoo SA, the terms of which are available on the https://www.odoo.com/documentation/17.0/legal/terms/enterprise.html website.

Data processed by Baulders’ AI and virtual assistant engine uses the GPT-4 model and is sent to OpenAI. For this reason, do not use AI assistance on any sensitive data (passwords, codes, secret and sensitive data, etc.). Details of OpenAI’s procedures for data use and security are available and described on the https://openai.com/enterprise-privacy website.

Users must agree and comply with these terms.

For specific hosting, storage and automatic data processing requirements, Premium and On-Premises solutions are available on request at contact@baulders.com.

BAULDERS undertakes to take all necessary technical and organizational measures and precautions to preserve the security of information. However, in the event of an incident affecting the integrity or confidentiality of the customer’s personal data, BAULDERS must inform the customer as soon as possible and notify the customer of the appropriate corrective measures implemented. 

The user’s personal data may be processed by BAULDERS’ subcontractors (service providers) exclusively for the purposes of this privacy policy. 

Within the limits of their respective attributions and for the purposes mentioned above, the main persons likely to have access to BAULDERS user data are mainly our customer service employees.

In the event of a data breach and in accordance with Articles 33 and 34 of the DGPR, BAULDERS undertakes to notify the French supervisory authority (the CNIL), as well as, if required, the individuals affected by the data breach.

If the subscription expires, the data stored on Baulders will be kept for 03 months and then permanently deleted.

If the customer requests to unsubscribe, the data stored on BAULDERS will be permanently deleted.

BAULDERS respects the intellectual property of the data stored on BAULDERS by the Customer ( Account Manager ) which remains at all times that of the Customer. The respect of the rights must be imposed in the contracts that bind the Customer with his employees and his service providers, with whom the Customer shares certain access to the data through BAULDERS. The Customer is responsible for the intellectual property of documents uploaded to BAULDERS on his workspace.

No data will be stored in BAULDERS data libraries without the express agreement of the project rights holder.

2.7 International users

In the event that the user does not reside in France, he consents to the collection, processing and storage of his personal data outside his jurisdiction and in accordance with this privacy policy. He therefore submits to the application of French law.

2.8 Individual rights

With regard to Articles 15 to 22 of the GDPR, you have the right to access (Article 15 GDPR), rectify (Article 16 GDPR), erase (Article 17 GDPR), object (Article 21 GDPR), portability (Article 20 GDPR), and withdraw consent (Article 13-2c GDPR) to your personal data when this same consent constitutes the legal basis for processing.

You also have the right to lodge a complaint with the CNIL (https://www.cnil.fr/fr/plaintes). 

2.9 Minors

The services offered by Baulders are intended for users over the age of 18 in the context of their professional activity. Baulders does not store any data on persons under the age of 18. 

2.10 Data transfer outside the European Union

BAULDERS may not process, host or transfer information collected on its customers to a country outside the European Union without prior notice to the customer. 

However, BAULDERS remains free to choose its technical and commercial subcontractors on condition that they present a sufficient guarantee with regard to the requirements of the General Data Protection Regulation (GDPR).

2.11 Awareness-raising

Our employees receive appropriate training on the protection of personal data. 

2.12 Register of processing operations

In accordance with Article 30 of the GDPR, BAULDERS keeps a register of personal data processing containing information such as the purposes of processing, a categorization of personal data or a description of transfers to recipients and transfers outside the European Union. 

3. Cookie policy

Cookies are text files sent and stored on the user’s computer by a web page server. They are used to facilitate user navigation. 

When you browse your website, information may be collected automatically via cookies.

Subject to your consent, BAULDERS may use cookies to improve the user experience. There are several types of cookies:

– Strictly necessary cookies. These are technical cookies, permanently active, which enable the site to function properly. They include, in particular, cookies that memorize your privacy preferences. 

– Performance cookies. These are functional cookies that enable us to measure the audience for our site’s content in order to improve its performance. 

– Personalization cookies. These are functional cookies that enable us to remember your site display preferences. They include, in particular, the display language selected. 

– Advertising cookies. These are advertising cookies that enable us to offer you relevant and interesting advertising on other websites, based on your browsing history, for example, according to your interests. 

3.1 Managing your cookies

As a user, you have the possibility of accepting or refusing all cookies, except those that are strictly necessary for the proper functioning of the BAULDERS website. 

You can modify your cookie settings at any time via the link: Set cookies

However, BAULDERS will not be held responsible for the inaccessibility of certain functionalities of the BAULDERS website caused by a restrictive cookie configuration. 

3.2 Cookie consent period

Cookie consent is valid for 6 months. Once this period has expired, your consent will be collected again. 

4. Internet tags

BAULDERS may occasionally use internet tags (“tags”, GIFs) and deploy them via a specialized partner. 

Internet tags are likely to be located (and therefore store the corresponding information, including the user’s IP address) in a foreign country.

These beacons are placed both in the online advertisements enabling users to access the site, and on the various pages of the site.

This technology enables BAULDERS to evaluate visitors’ responses to the site and the effectiveness of its actions (for example, the number of times a page is opened and the information consulted), as well as the user’s use of this site.

External service providers may collect information about visitors to the site and other websites through these tags in order to compile reports on site activity for BAULDERS, and to provide other website-related services.

5. Applicable law and jurisdiction

Any dispute arising in connection with the use of the BAULDERS website is subject to French law. Except in cases where the law does not allow it, exclusive jurisdiction is given to the competent courts of Paris.