Skip to content

Privacy Policy

Preamble

The SOFINORD group, of which ARMONIA is a division (hereinafter "the Group"), places great importance on the protection of personal data processed as part of its recruitment activities.

Data Controller

ARMONIA – Groupe SOFINORD
2 rue du Capitaine Scott
75015 Paris

acts as the data controller for the operations described in this Policy.

Personal data collected

As part of the recruitment process, ARMONIA may collect identification and contact information such as last name, first name, email address, postal address, and telephone number.

Information relating to the professional and academic background is also processed, including the curriculum vitae, diplomas, professional experience, and any information useful for assessing the application.

Exchanges with teams (interview dates, professional assessments, availability, salary expectations) may also be retained.

In some cases, publicly available information on professional networks may be viewed. When sensitive information is voluntarily provided by a candidate, it is processed in compliance with the safeguards set out by the regulations.

Purposes, legal bases, and retention periods

Processing of personal data is carried out in accordance with Regulation (EU) 2016/679 (GDPR), the amended French Data Protection Act, and the recommendations of the Commission nationale de l’informatique et des libertés (CNIL).

Data collected

The personal data that may be collected include, in particular, identification and contact information, information submitted via forms, application data, browsing data (IP address, connection logs, cookies, timestamps), as well as certain data made public by users on social networks.

The Group does not intend to collect sensitive data as defined by applicable regulations. However, if such data is voluntarily communicated by the data subjects, for example as part of an open message or application, it will be processed in strict compliance with the regulations and with an appropriate level of protection.

Institutional information on processing operations

Purpose of Processing 1: Site management

Description: Ensure operation, security, and availability of the Site

Categories of data: Technical data, logs, IP addresses

Legal basis(bases): Legitimate interest

Retention period: Maximum 12 months

Purpose of Processing 2: Managing requests

Description: Respond to requests submitted via the Site

Categories of data: Logs, system IDs, connection traces, data necessary for security

Legal basis(bases): Legitimate interest

Retention period: 3 years after last interaction

Purpose of Processing 3: Recruitment

Description: Application analysis, profile assessment, talent pool management

Categories of data: Identification data, professional background, information submitted

Legal basis(bases): Pre-contractual measures, legitimate interest, or consent depending on the case

Retention period: 2 years after last contact, unless objected to,

or for the duration of the contract if hired

Purpose of Processing 4: Security supervision and cyberdefense

Description: Prevention, detection, and management of security incidents

Categories of data: Identity, contact details, content of exchanges

Legal basis(bases): Legitimate interest and legal obligations

Retention period: 12 months, except where longer retention is necessary for an investigation or litigation

Purpose of Processing 5: Cookies, trackers & audience measurement

Description: Analyze traffic, improve the Site

Categories of data: Cookies, tracking pixels,  browsing data

Legal basis(bases): Consent, except for strictly necessary cookies

Retention period: 13 months from the placement of the cookie or the last interaction, depending on its nature

Purpose of Processing 6: Legal management & compliance

Description: Compliance with legal obligations, responses to authorities, audit

Categories of data: Data necessary for evidence and compliance with obligations

Legal basis(bases): Legal obligation / legitimate interest

Retention period: Applicable legal periods

Data recipients

Personal data collected when using the Site is accessible only to authorized persons within ARMONIA, within the limits of their respective duties, particularly internal departments involved in the pursued objectives (communications, human resources, management, legal, IT, and compliance).

This data may also be transmitted to service providers acting on behalf of the Group and involved in the operation of the Site and its associated tools, including technical service providers, hosting providers, publishers of digital solutions, or maintenance and support providers.

In certain cases, the data may be communicated to administrative, fiscal, or judicial authorities, or any legally authorized body, when required or permitted by current regulations.

All these recipients are subject to a strict obligation of confidentiality and security in accordance with the applicable regulations on personal data protection.

Transfers outside the EU

Data is primarily hosted within the European Union.

If transfers to countries outside the European Union are carried out, they are governed in accordance with applicable regulations, in particular through appropriate safeguards such as the standard contractual clauses adopted by the European Commission.

Security and resilience

The Group implements appropriate technical and organizational measures to ensure the security, integrity, and confidentiality of personal data, especially to prevent it from being altered, damaged, or accessed by unauthorized third parties.

Exercising your rights

In accordance with applicable regulations, data subjects have the right of access, rectification, erasure, restriction of processing, portability, as well as the right to object for reasons related to their particular situation. They also have the right to withdraw their consent at any time where the processing is based on it, as well as the right to define directives regarding the fate of their data after their death.

For any request regarding the exercise of your rights or any question related to the protection of personal data: dpo@sofinord.com

Data subjects also have the right to lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL) www.cnil.fr 

Update

This Policy may be amended to take account of legal, regulatory, or technical developments.

The version in force is the one published on the Site.

All we need is Armonia