Privacy Policy
Preamble
The SOFINORD group, of which ARMONIA is a division (hereinafter "the Group"), places great importance on the protection of personal data processed as part of its recruitment activities.
Data Controller
ARMONIA – Groupe SOFINORD
2 rue du Capitaine Scott
75015 Paris
acts as the data controller for the operations described in this Policy.
Personal data collected
As part of the recruitment process, ARMONIA may collect identification and contact information such as last name, first name, email address, postal address, and telephone number.
Information relating to the professional and academic background is also processed, including the curriculum vitae, diplomas, professional experience, and any information useful for assessing the application.
Exchanges with teams (interview dates, professional assessments, availability, salary expectations) may also be retained.
In some cases, publicly available information on professional networks may be viewed. When sensitive information is voluntarily provided by a candidate, it is processed in compliance with the safeguards set out by the regulations.
Purposes, legal bases, and retention periods
Processing of personal data is carried out in accordance with Regulation (EU) 2016/679 (GDPR), the amended French Data Protection Act, and the recommendations of the Commission nationale de l’informatique et des libertés (CNIL).
Data collected
The personal data that may be collected include, in particular, identification and contact information, information submitted via forms, application data, browsing data (IP address, connection logs, cookies, timestamps), as well as certain data made public by users on social networks.
The Group does not intend to collect sensitive data as defined by applicable regulations. However, if such data is voluntarily communicated by the data subjects, for example as part of an open message or application, it will be processed in strict compliance with the regulations and with an appropriate level of protection.
Institutional information on processing operations
Purpose of Processing 1: Site management
Description: Ensure operation, security, and availability of the Site
Categories of data: Technical data, logs, IP addresses
Legal basis(bases): Legitimate interest
Retention period: Maximum 12 months
Purpose of Processing 2: Managing requests
Description: Respond to requests submitted via the Site
Categories of data: Logs, system IDs, connection traces, data necessary for security
Legal basis(bases): Legitimate interest
Retention period: 3 years after last interaction
Purpose of Processing 3: Recruitment
Description: Application analysis, profile assessment, talent pool management
Categories of data: Identification data, professional background, information submitted
Legal basis(bases): Pre-contractual measures, legitimate interest, or consent depending on the case
Retention period: 2 years after last contact, unless objected to,
or for the duration of the contract if hired
Purpose of Processing 4: Security supervision and cyberdefense
Description: Prevention, detection, and management of security incidents
Categories of data: Identity, contact details, content of exchanges
Legal basis(bases): Legitimate interest and legal obligations
Retention period: 12 months, except where longer retention is necessary for an investigation or litigation
Purpose of Processing 5: Cookies, trackers & audience measurement
Description: Analyze traffic, improve the Site
Categories of data: Cookies, tracking pixels, browsing data
Legal basis(bases): Consent, except for strictly necessary cookies
Retention period: 13 months from the placement of the cookie or the last interaction, depending on its nature
Purpose of Processing 6: Legal management & compliance
Description: Compliance with legal obligations, responses to authorities, audit
Categories of data: Data necessary for evidence and compliance with obligations
Legal basis(bases): Legal obligation / legitimate interest
Retention period: Applicable legal periods
Data recipients
Personal data collected when using the Site is accessible only to authorized persons within ARMONIA, within the limits of their respective duties, particularly internal departments involved in the pursued objectives (communications, human resources, management, legal, IT, and compliance).
This data may also be transmitted to service providers acting on behalf of the Group and involved in the operation of the Site and its associated tools, including technical service providers, hosting providers, publishers of digital solutions, or maintenance and support providers.
In certain cases, the data may be communicated to administrative, fiscal, or judicial authorities, or any legally authorized body, when required or permitted by current regulations.
All these recipients are subject to a strict obligation of confidentiality and security in accordance with the applicable regulations on personal data protection.
Transfers outside the EU
Data is primarily hosted within the European Union.
If transfers to countries outside the European Union are carried out, they are governed in accordance with applicable regulations, in particular through appropriate safeguards such as the standard contractual clauses adopted by the European Commission.
Security and resilience
The Group implements appropriate technical and organizational measures to ensure the security, integrity, and confidentiality of personal data, especially to prevent it from being altered, damaged, or accessed by unauthorized third parties.
Exercising your rights
In accordance with applicable regulations, data subjects have the right of access, rectification, erasure, restriction of processing, portability, as well as the right to object for reasons related to their particular situation. They also have the right to withdraw their consent at any time where the processing is based on it, as well as the right to define directives regarding the fate of their data after their death.
For any request regarding the exercise of your rights or any question related to the protection of personal data: dpo@sofinord.com
Data subjects also have the right to lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL) www.cnil.fr
Update
This Policy may be amended to take account of legal, regulatory, or technical developments.
The version in force is the one published on the Site.