Third-Party Data Protection
Preamble
The SOFINORD group, of which ARMONIA is a division (hereinafter "the Group"), attaches great importance to the protection of personal data processed as part of its relationships with its clients, suppliers, service providers, lessors, partners, and more generally all third parties.
The Group operates in compliance with the General Data Protection Regulation (GDPR) and the amended French Data Protection Act (Loi Informatique et Libertés), and is committed to ensuring an appropriate level of protection in accordance with the applicable regulations and internal data protection governance principles.
Data Controller
ARMONIA – SOFINORD Group
2 rue du Capitaine Scott
75015 Paris
acts as the data controller for the operations described in this document.
Personal Data Collected
Depending on the nature of the relationship, ARMONIA may process identification and contact data (name, first name, business address, email address, phone number, position), administrative, contractual and financial data (bank details, documents necessary for invoicing or payment, legal identification numbers), data resulting from professional exchanges (correspondence, quotes, orders, operational information), as well as data necessary to comply with regulatory or compliance obligations (in particular as part of identity verification procedures for legal representatives or beneficial owners where required by applicable regulations).
To ensure the security of its information systems, ARMONIA may also process technical data such as connection logs, access traces, and technical event logs.
Purposes, Legal Bases and Retention Periods
Pre-contractual Management
Description: Supplier selection, responses to tenders, initial exchanges
Legal basis: Pre-contractual measures
Retention period: 3 years after the last contact
Execution of Contractual Relationships
Description: Monitoring of services, orders, deliveries, performance of contracts
Legal basis: Contract execution
Retention period: 6 years after the end of the business relationship (limitation period)
Administrative, Accounting, and Financial Management
Description: Quotes, invoicing, payments, mandatory accounting operations
Legal basis: Legal obligation / contract execution
Retention period: 10 years (accounting documents)
B2B Commercial Prospecting
Description: Business development, prospecting activities
Legal basis: Legitimate interest
Retention period: 3 years from the last contact
Due Diligence and Compliance
Description: Regulatory checks, compliance obligations
Legal basis: Legal obligation / legitimate interest
Retention period: Applicable legal periods
Debt Collection and Litigation
Description: Reminders, formal notices, legal proceedings
Legal basis: Legitimate interest / legal obligation
Retention period: Until all remedies have been exhausted
Information System Security
Description: Prevention and detection of incidents, logging, access monitoring
Legal basis: Legitimate interest / legal obligation
Retention period: Maximum 12 months for technical logs
Management of Requests Submitted via the Site
Description: Processing of requests and messages received
Legal basis: Legitimate interest
Retention period: 3 years after the last contact
Data Recipients
The data is intended for authorized internal ARMONIA departments (notably sales, operations, legal, financial, and management). It may be transmitted to third-party service providers acting on behalf of the Group (IT, accounting, financial service providers), as well as to legally authorized authorities (statutory auditors, administrative or judicial authorities, tax or social bodies).
Third-party recipients are bound by a strict obligation of confidentiality and security in accordance with applicable regulations.
Transfers outside the European Union
The data is mainly hosted within the European Union.
If data is transferred outside the European Union, such transfer is strictly governed by the safeguards provided for in the GDPR, notably through the implementation of standard contractual clauses adopted by the European Commission and, where applicable, by appropriate additional measures.
Data Security
ARMONIA implements appropriate technical and organizational measures to protect personal data, including network security systems (firewalls, network segmentation, secure access), access management mechanisms, monitoring and incident detection tools, and encryption measures where necessary.
Regular controls ensure the maintenance of a security level that complies with Group standards and applicable regulatory requirements.
Rights of Data Subjects
In accordance with applicable regulations, data subjects have the right to access, rectify, erase, restrict processing, data portability, as well as the right to object on grounds relating to their particular situation. They also have the right to withdraw their consent at any time where processing is based on consent, as well as the right to define directives regarding the fate of their data after their death.
For any request relating to the exercise of your rights or for any question regarding personal data protection: dpo@sofinord.com
Data subjects also have the right to lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL) www.cnil.fr
Updates
This document may be modified to take into account legal, regulatory, or technical developments. The applicable version is the one published on the Site.