Skip to content

Third-Party Data Protection

Preamble 

The SOFINORD group, of which ARMONIA is a division (hereinafter "the Group"), attaches great importance to the protection of personal data processed as part of its relationships with its clients, suppliers, service providers, lessors, partners, and more generally all third parties.  

 The Group operates in compliance with the General Data Protection Regulation (GDPR) and the amended French Data Protection Act (Loi Informatique et Libertés), and is committed to ensuring an appropriate level of protection in accordance with the applicable regulations and internal data protection governance principles. 

Data Controller 

ARMONIA – SOFINORD Group 
2 rue du Capitaine Scott 
75015 Paris 
acts as the data controller for the operations described in this document.

Personal Data Collected 

Depending on the nature of the relationship, ARMONIA may process identification and contact data (name, first name, business address, email address, phone number, position), administrative, contractual and financial data (bank details, documents necessary for invoicing or payment, legal identification numbers), data resulting from professional exchanges (correspondence, quotes, orders, operational information), as well as data necessary to comply with regulatory or compliance obligations (in particular as part of identity verification procedures for legal representatives or beneficial owners where required by applicable regulations). 

To ensure the security of its information systems, ARMONIA may also process technical data such as connection logs, access traces, and technical event logs. 

Purposes, Legal Bases and Retention Periods

Pre-contractual Management 

Description: Supplier selection, responses to tenders, initial exchanges 

Legal basis: Pre-contractual measures 

Retention period: 3 years after the last contact

Execution of Contractual Relationships 

Description: Monitoring of services, orders, deliveries, performance of contracts 

Legal basis: Contract execution 

Retention period: 6 years after the end of the business relationship (limitation period)

Administrative, Accounting, and Financial Management 

Description: Quotes, invoicing, payments, mandatory accounting operations 

Legal basis: Legal obligation / contract execution 

Retention period: 10 years (accounting documents)

B2B Commercial Prospecting 

Description: Business development, prospecting activities 

Legal basis: Legitimate interest 

Retention period: 3 years from the last contact

Due Diligence and Compliance 

Description: Regulatory checks, compliance obligations 

Legal basis: Legal obligation / legitimate interest 

Retention period: Applicable legal periods

Debt Collection and Litigation 

Description: Reminders, formal notices, legal proceedings 

Legal basis: Legitimate interest / legal obligation 

Retention period: Until all remedies have been exhausted

Information System Security 

Description: Prevention and detection of incidents, logging, access monitoring 

Legal basis: Legitimate interest / legal obligation 

Retention period: Maximum 12 months for technical logs

Management of Requests Submitted via the Site 

Description: Processing of requests and messages received 

Legal basis: Legitimate interest 

Retention period: 3 years after the last contact

Data Recipients 

The data is intended for authorized internal ARMONIA departments (notably sales, operations, legal, financial, and management). It may be transmitted to third-party service providers acting on behalf of the Group (IT, accounting, financial service providers), as well as to legally authorized authorities (statutory auditors, administrative or judicial authorities, tax or social bodies). 

Third-party recipients are bound by a strict obligation of confidentiality and security in accordance with applicable regulations. 

 

Transfers outside the European Union 

The data is mainly hosted within the European Union. 

If data is transferred outside the European Union, such transfer is strictly governed by the safeguards provided for in the GDPR, notably through the implementation of standard contractual clauses adopted by the European Commission and, where applicable, by appropriate additional measures. 

 

Data Security 

ARMONIA implements appropriate technical and organizational measures to protect personal data, including network security systems (firewalls, network segmentation, secure access), access management mechanisms, monitoring and incident detection tools, and encryption measures where necessary. 

Regular controls ensure the maintenance of a security level that complies with Group standards and applicable regulatory requirements. 

 
Rights of Data Subjects 

In accordance with applicable regulations, data subjects have the right to access, rectify, erase, restrict processing, data portability, as well as the right to object on grounds relating to their particular situation. They also have the right to withdraw their consent at any time where processing is based on consent, as well as the right to define directives regarding the fate of their data after their death. 

For any request relating to the exercise of your rights or for any question regarding personal data protection: dpo@sofinord.com  

Data subjects also have the right to lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL) www.cnil.fr

Updates 

This document may be modified to take into account legal, regulatory, or technical developments. The applicable version is the one published on the Site.

All we need is Armonia