CONFIDENTIALITY CHARTER
WHO ARE WE?
CAIRN SPORT SAS, a simplified shareholding company, société par actions simplifiée, registered on the Bourg-en-Bresse Companies and Business register under number 318 197 902, whose registered office is situated at 772 rue de l’Industrie, 01390 Saint-André-de-Corcy (hereinafter “CAIRN”) is the personal data controller for the purposes set out below.
The purpose of this Charter is to provide you with information on how we collect your personal data whilst strictly respecting your rights.
PURPOSES AND LEGAL BASES
The schedule below sets out the purposes for which CAIRN processes your personal data:
Processing Purposes | Legal Bases |
Managing contact requests | Our legitimate interests (responding to your requests and helping you to find and choose products) |
Managing access to customer accounts | Fulfilling the contract between us and protecting our legitimate interests (ensuring that the Internet Site is kept secure) |
Managing orders | Fulfilling our contract or our legitimate interests relating to data which is in excess of that strictly necessary for executing the contract |
Sales prospecting | Our legitimate interests (providing information on the latest products, sending promotional offers and improving customers’ experience) or your consent where this is required by legislation. |
For statistical purposes | Our legitimate interests (improving our sales proposals) |
Managing claims | Fulfilling our contract and our legitimate interests (improving our sales proposals and customers’ experience) |
Measuring Internet Site frequency | Our legitimate interests (managing and improving frequency on our site) or your consent where this is required by regulations (based on the type of cookies used) |
Managing customer feedback and satisfaction surveys | Our legitimate interests (promotions and improving our sales proposals) |
Managing recruitment | Our legitimate interests in examining applications and your consent for them to be retained on a CV filing system. |
Managing Disputes | Our legitimate interests (in defence of our interests) and fulfillment of our contractual relations. |
CAIRN has appointed a Data Protection Officer (DPO) who may be contacted:
- by email at dpo@cairn-sport.com
- or by mail at the following address: CAIRN SPORT – DPO, 772 rue de l’Industrie ZI la Sereine 01390 Saint-André-de-Corcy
WHAT DATA DO WE PROCESS AND FOR HOW LONG DO WE RETAIN IT?
Data which is processed is: identification data (surname, first name, contact references etc) data relating to your centres of interest and data relating to contracts and payments. It also relates to your professional skills, your CV and your qualifications in relation to applications for employment.
Information collected by CAIRN which is essential to meet the purposes mentioned above is identified by an asterisk on data collection forms. If you do not complete obligatory fields, CAIRN will not be able to provide the service in question.
Data is collected by CAIRN directly from the person concerned or provided by our marketing partners.
Your personal data, which is processed by CAIRN is held pursuant to regulations relating to the protection of data and according to durations prescribed by law. For example, data relating to prospects is held for three years from the last commercial contact. Data from employment applicants is held for two years with their consent.
WHO HAS ACCESS TO YOUR DATA?
Your personal data is principally provided or made accessible to CAIRN staff who are responsible for Commercial and Marketing aspects, Information systems security Department, Financial Department and Legal Department and Human Resources Department.
Your data may also be disclosed to:
- CAIRN computer service providers (external service providers maintaining computer systems for example)
- Subcontractors working for the purposes of sales prospection (routing etc.)
- Companies in the same group as CAIRN (the 2-RIDE Group)
Subcontractors acting in accordance with CAIRN instructions will be bound to implement appropriate protection measures.
Where some CAIRN partners are established outside the European Union we ensure that transfers are carried out in compliance with French regulatory requirements (for example setting up contractual clauses which have been adopted by the European Commission). You may contact the CAIRN Data Controller to obtain further information on these subjects and a copy of relevant documents.
WHAT ARE YOUR RIGHTS?
- You have the right to request access to your personal data.
- You have the right to request correction to your personal data.
- You have the right to request limits to the processing of your personal data (i) where you dispute the accuracy of your data, for a period enabling us to check its accuracy, (ii) where you consider that we are illegally processing your data and you require a limit to its use rather than deletion, (iii) where we no longer have need of your data having regard to the purposes set out above but these are still necessary for recognition, exercise or defence of your legal rights, (iv) in the event of exercising your right to opposition during the verification period relating to whether the legitimate grounds that we have take precedence over those that you have.
- You have the right to request deletion to your personal data.
- You have the right to request exercise of your rights to opposition relating to processing used for reasons relating to your particular situation.
- You have the right, at any time without any requirement to provide reasons, to oppose marketing prospection.
- You have the right not to be subject to a decision exclusively based on automatic processing resulting in legal consequences relating to you or significantly affecting you.
- You have the right to exercise your rights to portability of data which gives you the right to obtain a copy of your data and to transfer it to a third party in a format which is structured and currently in use and machine-readable.
- You have the right to withdraw your consent at any time where processing your data is based on this consent.
- You also have the right to give instructions relating to holding, deletion and communication of your personal data post-mortem.
Where you have a customer account, you may carry out most of these procedures directly by connecting to this customer account.
Otherwise, these rights may be exercised at any time by sending an email to: dpo@cairn-sport.com or by post to the following address: CAIRN SPORT – DPO, 772 rue de l’Industrie ZI la Sereine 01390 Saint-André-de-Corcy
You may also, if you wish, make a claim to the Personal Data Protection Commission, the Commission Nationale de l’Informatique et des Libertés (CNIL). Additional information is available on their Internet Site at www.cnil.fr.