Dative

Privacy policy

Collection and use of personal data when using the connected services of DATIVE's applications.

1. General information regarding the processing of personal data

This privacy policy provides important information about your rights related to the processing of your personal data and the legal basis on which your personal data is processed in connection with the use of DATIVE's connected services.

1.1. Data controller

The entity responsible for processing your personal data is DATIVE.


You can contact DATIVE at the following address:

DATIVE

100 Rue de Norvège 69125 Colombier-Saugnieu

dev@dative-gpi.com

+33 (0)4 72 47 80 58

Company registration number: 879 916 344 (RCS Lyon)


For any information regarding the exercise of your rights, please contact dev@dative-gpi.com. Further details about your rights can be found in the section titled "2. Your rights" of this privacy policy.

1.2. Purpose of data processing for the use of connected services

1.2.1. Contract conclusion and execution for online mobile services

We process your personal data, including your email address, password, name, and phone number provided during registration for connected services, to conclude or execute the service contract for connected services (Art. 6(1)(b) GDPR).


If you are using the services as a user, we process your personal data to fulfil our contractual obligations (Art. 6(1)(b) GDPR). Details about the concept of a user can be found in section "3. Detailed Data Processing".


When using connected services, your email address, password, name, phone number, location, and the unique identifier of your mobile devices are processed. Detailed information about which data is processed and the roles of different users can be found in section "3. Detailed Data Processing".

1.2.2. Technical availability and security of connected services

To provide the services, your email address and password are used for clear identification and to verify your authorisation to access our products' services. This ensures that unauthorised individuals are prevented from accessing the services. Data processing is carried out to provide the services (Art. 6(1)(b) GDPR) and is necessary for user authentication and establishing secure communication with the data server.

1.2.3. Identification process

Data is only processed after obtaining your consent (Art. 6(1)(a) GDPR) and solely for the purpose of enabling the relevant connected services. Detailed information is available in section "3. Detailed Data Processing".

1.3. Data deletion and rectification

You can correct the data entered in your user account settings at any time (provided you have created an account).


You may also request the deletion of all your data at any time by submitting a request via the contact form available at:

https://www.dative-gpi.com/contact

1.4. Data recipients

1.4.1. Data server

Personal data is processed on our servers exclusively on our behalf and according to our instructions.

1.4.2. Other recipients

Personal data is not shared with any third party.

2. Your rights

2.1. Right of access

You have the right to request confirmation of whether your personal data is being processed and, if so, what personal data is being processed and to which third parties, within and outside the European Union, it has been disclosed. Additionally, you may request a copy of your processed personal data.

2.2. Right to rectification

You have the right to request correction of inaccurate or incomplete personal data concerning you.

2.3. Right to erasure

You can request the erasure of your data if the conditions outlined in Art. 17 GDPR are met. For example, you can request data deletion when it is no longer necessary for the purposes for which it was collected or when processing is based on your consent, and you withdraw it.

2.4. Right to restrict processing

You have the right to restrict data processing if the conditions of Art. 18 GDPR are met. For instance, if you dispute the accuracy of your data, you can request restriction of processing while the data's accuracy is being verified.

2.5. Right to object

You have the right to object to the processing of your data in the following cases:

• When processing is carried out for direct marketing purposes (including profiling for direct marketing).

• When processing (including profiling) is based on:

• The performance of a task carried out in the public interest or in the exercise of official authority (Art. 6(1)(e) GDPR).

• Legitimate interests pursued by us or a third party (Art. 6(1)(f) GDPR), unless we can demonstrate compelling legitimate grounds that override your interests, rights, or freedoms or the processing is necessary for the establishment, exercise, or defence of legal claims. In the event of an objection, please explain the reasons why you oppose the data processing.

2.6. Right to data portability

When processing is based on consent or the performance of a contract and is carried out by automated means, you have the right to request that your data be provided in a structured, commonly used, and machine-readable format and to transmit this data to another data controller.

2.7. Right to withdraw consent

When processing is based on consent, you can withdraw your consent at any time, free of charge, by emailing dev@dative-gpi.com or using the contact details in the legal notice, with effect for the future.

2.8. Right to lodge a complaint

In the event of a dispute regarding the exercise of your rights, you have the right to lodge a complaint with the relevant data protection authority. A list of data protection authorities in the European Union can be found here:

https://edpb.europa.eu/about-edpb/about-edpb/members_en

In France, the competent authority is the National Commission for Informatics and Liberties (CNIL): 3 Pl. de Fontenoy, 75007 Paris.

3. Detailed data processing

3.1. Email address

The email address is used to create and log in to a user account. It may also be used for communication to notify the user of significant events. Users can opt out of receiving emails. The email address is not shared with third parties.

3.2. Password

The password is used for account creation and login. It is securely stored and never shared with third parties.

3.3. Name

The name is used for personalising the user interface and facilitating identification among users. It is not shared with third parties.

3.4. Phone number

The phone number may be used for communication, such as notifying users of significant events. Users can opt out of receiving SMS notifications. The phone number is not shared with third parties.

3.5. Location

Location data may be used to inform users about login locations. This data processing can be declined by the user and is not shared with third parties.

3.6. Unique mobile device identifier

This identifier may be used to display which devices have accessed the user account. It is not shared with third parties.