Cogelec Intratone

PRIVACY POLICY
COGELEC – Data Processor
(Version as of 28.05.2026)

1. Definitions

COGELEC: refers to the parent company COGELEC, SA with a Board of Directors, with a capital of 4,004,121.60 euros, registered with the Trade and Companies Register of LA ROCHE SUR YON, under number 433.034.782, whose registered office is located at 370 rue de Maunit - 85290 Mortagne-sur-Sèvre France. COGELEC is a French manufacturer of access control, intercom and access security solutions that markets its products and solutions under the brands Intratone®, Rozoh®, Hexact®, Kibolt®.

COGELEC Group: refers to the group of companies formed by COGELEC and its subsidiaries INTRATONE UK, INTRATONE GMBH and INTRATONE BV.

End Customer: means the legal and/or natural person who decides to install and use the Products manufactured by COGELEC and marketed either directly by the COGELEC Group or indirectly by authorized distributors/installers. The End Customer is the Data Controller (social landlord, trustee, public or tertiary institution).

Personal Data: refers to any information making it possible to directly or indirectly identify a Data Subject.

Incident: refers to any event, accidental or malicious, which affects the security of a data medium (Personal Data or not), such as a cyberattack, fire, flood, loss or theft of equipment, and which is likely to lead to a Personal Data Breach. An Incident does not always lead to such a Breach.

Data Subject: refers to any natural person whose Personal Data is processed by the End Customer, in the context of the performance of the Services.

Products: refers to all equipment manufactured by COGELEC such as intercom, access control or access security devices.

Associated Services: correspond to remote management and networking services provided by COGELEC and allowing the use of the Products sold and the management of access in the equipped premises (intercom and access control services, programming and access to the management platform and applications, license on embedded software, maintenance and deployment of computer servers, synchronization and updating of access control functional data, after-sales service and technical support, telephone support, documentation, etc.).

Sites/Management Platforms: refers to the sites allowing the End Customer to configure an intercom or access control equipment. These include www.intratone.info, www.web.hexact.fr, www.organigramme.info or www.rozoh.info.

Pseudonymisation: refers to the processing of Personal Data in such a way that it can no longer be attributed to a specific Data Subject without the use of additional information, provided that this additional information is kept separately and subject to technical and organisational measures to ensure that the Personal Data is not attributed to an identified or identifiable natural person.

Applicable Regulation: refers to Regulation No.2016/679 relating to the protection of natural persons with regard to the processing of Personal Data [or GDPR] and to the free movement of such Personal Data and Law No.78-17 of 6 January 1978 relating to data processing, files and freedoms [or LIL]. The GDPR is applicable in all territories of the European Union as well as in the territory of the UK with the UK-GDPR and the Data Protection Act 2018 (DPA Act-2018) which has benefited from an adequacy decision since 28 June 2021.

Data Controller: refers to the person (natural or legal) who, alone or jointly with others, determines the purposes of the Processing (why the data processing is implemented), as well as its means (how it is implemented).

Data Processor/Subcontractor: means the natural or legal person who Processes in the name and on behalf of the Controller of Personal Data.

Processing: refers to a set of operations carried out on Personal Data, such as collection, organization, recording, access, playback, storage, backup, restoration, restitution, destruction.

Personal Data Breach or Breach: means a breach of security resulting in the destruction, loss, alteration, unauthorized disclosure or illegal or accidental access to Personal Data transmitted, stored or Processed.

2. Policy Overview

2.1 Introduction

COGELEC is a French manufacturer of wireless intercoms, access control and access security solutions, present in several countries in Europe.

The COGELEC Group markets its products and solutions mainly to social landlords, trustees, distributors and installers who wish to set up access control systems for the residential sector. It also markets them in the tertiary sector, to companies and communities seeking to secure access to their premises.

Aware of the importance of ensuring the security and confidentiality of the Personal Data of Data Subjects on behalf of the End Customer, the COGELEC Group makes strong commitments to them.

Its approach falls within the framework of the Applicable Regulations, as well as the doctrine of the European Data Protection Board (EDPS) and the national competent authorities specific to each country where the Data Subjects are located.

The commitments of the COGELEC Group could evolve according to the legal and regulatory context, the decisions of the competent judges and the doctrine of the EDPS and the competent authorities, in particular the CNIL in France, which is the lead authority for the COGELEC Group.

Countries concernedCompetent authorities
FranceCommission Nationale de l'Informatique et des Libertés (CNIL)
United KingdomInformation Commissioner's Office (ICO)
GermanyBundesbeauftragte für den Datenschutz und die Informationsfreiheit = At federal level, it is the Federal Commissioner for Data Protection and Freedom of Information (BfDI)
NetherlandsAutoriteit Persoonsgegevens (AP) Dutch Data Protection Authority
BelgiumData Protection Authority/Gegevensbeschermingsautoriteit
LuxembourgNational Commission for Data Protection (CNPD)

2.2 Value

The Policy has no contractual value. It recalls the legal obligations and commitments to which the COGELEC Group companies and the End Customer are bound. It does not bind the Data Subjects and does not impose obligations on them but grants them rights.

2.3 Objectives

The purpose of the Policy is to centralize in a single document, in a clear and concise manner, information on the measures and commitments taken by the COGELEC Group, when it Processes the Data Subjects' Data in the name and on behalf of the Data Controller.

3. Scope of the Policy

3.1 Material scope

The Policy applies to the Processing of Personal Data carried out by the Data Controller when using the Associated Services and especially the Management Platforms hosted and maintained by COGELEC. It therefore applies to the Processing established by the COGELEC Group as a Data Processor.

Conversely, the Policy does not apply to Processing carried out by the COGELEC Group when it acts as Data Controller, namely in its commercial relations with its customers (a dedicated policy is available).

3.2 Legal and territorial scope

The Policy applies to the COGELEC Group and the End Customer insofar as they are established in the territory of the European Union or the EEA, the United Kingdom, Switzerland and Monaco and Process Data Subject Data which are also located in these territories.

4. Legal status of the COGELEC Group and the End Customer

As part of their relations, the COGELEC Group and the End Customer undertake to comply with the Applicable Regulations according to its territorial location.

The End Customer is the Data Controller and the COGELEC Group acts as Data Processor. The End Customer expressly authorises the COGELEC Group, acting as Data Processor, to Process in its name and on its behalf the Personal Data necessary for the performance of the Associated Services.

COGELEC has appointed a Data Protection Officer ("DPO"). The DPO centralises data protection management for all COGELEC Group companies in accordance with Art. 37.2 of the GDPR and is assisted, where appropriate, by specialist lawyers in each country where the COGELEC Group is represented.

IdentitySPARLANN Contact Information
Sarah BENGUIGUI[email protected]
INTRATONE UK Power Road Studios, 114 Power Road, London, W4 5PY
Company number: 1120035
+44 (0)208 037 9012 – [email protected]
INTRATONE GMBH Niederkasseler Lohweg 191 40547 Düsseldorf
Registration number: HRB 338
+49 (0)211 601 770 0 – [email protected]
INTRATONE NL Kuiperbergweg 40 1101 AG AMSTERDAM
Registration number (RSIN): 859300432
+31 (0)20 788 3401 – [email protected]

5. Commitments of the COGELEC Group

The COGELEC Group undertakes to:

  1. Process Personal Data only for the purposes that are the subject of the implementation of the Processing of Personal Data in the context of the performance of the Associated Services;
  2. Process Personal Data in accordance with the documented instructions of the Data Controller;
  3. Guarantee the confidentiality of the Personal Data Processed in the context of the performance of the Associated Services;
  4. Ensure the implementation of appropriate technical and organisational measures;
  5. Ensure that COGELEC Group persons authorised to Process Personal Data in the name and on behalf of the Data Controller:
    1. Undertake to respect confidentiality or be subject to an appropriate legal or contractual obligation of confidentiality;
    2. Receive the necessary training in the protection of Personal Data.
  6. Take into account, with regard to its tools, Products, Associated Services, the principles of data protection by design and protection by default.

6. Commitments of the Data Controller

The Data Controller undertakes to:

  1. Provide the COGELEC Group with the only Personal Data necessary for the Processing (principle of minimization);
  2. Document in writing any instructions regarding the Processing of Personal Data by the COGELEC Group;
  3. Ensure, in advance and throughout the duration of the Processing, compliance with the obligations provided for by the Applicable Regulations by its agents and/or employees, collaborators or service providers or agents, and in particular the installer of the equipment which would not be of the choice of the COGELEC Group;
  4. At the time of collection of Personal Data: inform the Data Subject of the purpose of the Processing, the legal bases and the role of the COGELEC Group in the processing of personal data:
    1. Obtain, if necessary, the consent of the Data Subject under the conditions set out in Articles 7 and 8 of the GDPR;
    2. Inform the Data Subject of the Processing of Data concerning them and of their rights under Articles 15 et seq. of the GDPR;
  5. Update the Personal Data of a Data Subject and ensure their accuracy;
  6. Immediately inform the COGELEC Group of any Incident observed during the use of the Associated Services and especially the Management Sites and originating from a defect related to COGELEC's Associated Products/Services so that the latter can remedy it;
  7. Cooperate with and assist the COGELEC Group to enable it to comply with its obligations regarding the protection of Personal Data;
  8. Implement appropriate technical and organisational measures to ensure and be able to demonstrate that the Processing is carried out in accordance with Article 32 of the GDPR.

7. Characteristics of Processing

The Policy relates only to Processing implemented by the Data Controller and subcontracted to the COGELEC Group.

Nature of operations carried out on Personal DataTransmission to the programming service and configuration of the equipment (if the service is ordered), provision of an online Management Platform, hosting of Personal Data and assistance to the End Customer.
Processing carried outAccess, playback, collection, integration, organization, storage, recording, backup, modification, extraction, restoration, restitution, destruction, erasure.
Duration of the ProcessingAs long as the Data Controller wishes to benefit from the Associated Services and until the end of the reversibility operations.
Purpose(s) of the Processing pursued by the Data ControllerImplementation of devices to control and secure access to buildings/sites equipped by the Data Controller.
Personal Data Processed Residents: occupants, tenants, owners whether private or professional, employees, agents – Users = employees, agents, employees

Directly collected data: Surname, first name, home or work address, telephone numbers, apartment number, badge number.
Automatic data collection: IP address of equipment, intercom and mobile brand and model, logs of connection to the Management Site/mobile application, events: date and time of opening of the door (badges or audio/video connections)

Users of the Management Sites designated by the End Customer: Surname, first name, email, position, IP or login credentials, cookie ID

8. Data retention of the Data Controller

Unless otherwise instructed by the Data Controller, Personal Data is kept by COGELEC under the conditions and in the manner described below.

8.1 Shelf life

8.1.1 Principle

In principle, Personal Data is kept for as long as the End Customer wishes to benefit from the Associated Services.

Thus, as long as the Personal Data of the resident or user benefiting from the access control device (intercom, badge, etc.) are processed by the End Customer through COGELEC's Management Platforms, and are not deleted by the End Customer, the Data are kept on COGELEC's servers.

8.1.2 Programming service

As part of the "turnkey" Service, the COGELEC Group proposes to the End Customer to ensure in its name and on its behalf the programming of the Products and Personal Data of residents/users via the Management Site, to respond to a request for assistance from the End Customer and identify potential input errors.

In the context of this Associated Service, the files are kept for the time necessary for the operations of configuring the Products. Following the programming operations, the files are kept for an additional three (3) months for the End Customer's assistance. They are then deleted.

8.1.3 Events – passage histories

In residential configurations, "events" (access logs including, in particular, the equipment used, the action performed, and the date and time of access) are, by default, not accessible in a nominative manner to the Data Controller and/or the manager of the Management Platform.

In accordance with CNIL recommendations relating to access control systems in collective residential buildings, the events visible from the Management Platform are anonymised in order to prevent any use of the system for monitoring residents.

The Data Controller configures the Management Platform itself and remains solely responsible for the settings it chooses to activate and the purposes pursued in this context.

Depending on the purposes pursued, COGELEC may act either as a data controller or as a data processor:

No other processing or operation is carried out on the events. At the end of the three (3) month retention period, the events are anonymised. The anonymisation process consists of permanently deleting the link between the badge identifier and the associated events (door used, action performed, timestamp). This process is irreversible.

8.2 Data Restitution and Deletion

Personal Data may be deleted by the End Customer directly on the Management Site, for example, when a Data Subject leaves a residence or its functions authorizing it to access a building or an equipped site.

Personal Data may also be deleted at the request of the Data Subject in the context of the implementation of Article 17 of the GDPR, subject to compliance with the applicable conditions. Such a request for deletion shall be made to the End Customer.

At the end of the Associated Services and at any time, upon the written and prior request of the End Customer, the Data shall be returned to the End Customer within an appropriate period, not exceeding thirty (30) working days, from the receipt of the request by COGELEC. In agreement with the End Customer, this period may be extended.

The Personal Data will be returned to the End Customer in the same format as that used by the Data Controller to make the Personal Data available to COGELEC or, failing that, in the available export(s), and at no additional cost to the latter. To date, the available format is Excel, ".xlsx" or ".xls".

The return may be the subject of a report signed between the Parties, at the request of the Data Controller.

COGELEC permanently destroys, three (3) months after programming, the copies of the Personal Data held in its systems, unless the legislation imposed on COGELEC prevents it from returning or destroying all or part of the Personal Data. COGELEC may provide proof of this to the End Customer simultaneously with the signing of the return report.

9. Processing Activity Register

COGELEC declares to keep in writing a register of all categories of Processing activities carried out in the name and on behalf of the End Customer, Data Controller, including:

10. End Customer Support/Technical Support

10.1 Principle

The COGELEC Group undertakes to assist and collaborate with the End Customer in order to enable the latter to comply with its obligations under the Applicable Regulations.

10.2 Assistance in case of exercise of rights by Data Subjects

The Data Controller is solely responsible for managing the requests of the Data Subjects.

The COGELEC Group undertakes, within a period not exceeding ten (10) days and without directly acceding to the request of the Data Subjects, to cooperate with the Data Controller in the event that the latter is requested in the context of the performance of its obligation to respond to requests for the exercise of the rights of the Data Subjects (access, rectification, erasure, opposition, portability, etc.) to:

  1. Transmit to the End Customer, any request and/or any sufficiently informed request from a Data Subject for the exercise of their rights under the Applicable Regulations;
  2. From the aforementioned information, cooperate if necessary with the End Customer and provide it with the necessary information within an appropriate time to enable the End Customer to respond to the Data Subjects;
  3. In all cases and where appropriate, implement and have implemented by the Sub-Processors, any request from the Data Controller concerning the rights of the Data Subjects.

10.3 Duty to alert the End Customer

If the COGELEC Group considers that an instruction constitutes a violation of the Applicable Regulations, any other provision of Union law or the law of the Member States relating to the protection of Personal Data, it shall immediately inform the End Customer. However, the COGELEC Group is not required to check whether any instruction given by the Data Controller complies with the Applicable Regulations.

The COGELEC Group may not, under any circumstances, be held liable in the event of unlawful instructions from the End Customer, constituting a violation of the Applicable Regulations.

11. Data Security

11.1 Commitments of COGELEC

Taking into account the state of knowledge, the implementation costs, the nature, scope, context and purposes of the Processing as well as the risks to the rights and freedoms of Data Subjects, the COGELEC Group implements the appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

For the choice of measures, COGELEC refers in particular to the state of the art and the recommendations of the competent authorities such as the CNIL or the ANSSI.

All the measures taken by the COGELEC Group to guarantee the confidentiality, availability, integrity and traceability of Personal Data are described in the Data Processor's "Security Assurance Plan" available on request. A summary of this plan is attached to this policy.

The COGELEC Group may modify the security measures at any time, without having to inform the End Customer, the Data Controller, in advance and update its information in this document.

11.2 End Customer Commitments

The End Customer is required to take all necessary precautions, with regard to the nature of the Personal Data and the risks presented by the Processing, to preserve the security of the Personal Data and, in particular, to prevent it from being distorted, damaged or accessed by unauthorised third parties.

Thus, the End Customer undertakes to take all necessary protective measures to ensure:

12. Personal Data Breach

In summary, in the event that an Incident has an impact (destruction, loss, alteration, unauthorized access or disclosure of Personal Data, etc.) on the End Customer's Personal Data processed by COGELEC, the procedure followed is described below.

12.1 Consideration by the DPO of the Incident and its documentation

The DPO checks the documents transmitted, the data impacted and in particular whether the End Customer's Personal Data has been affected.

12.2 Qualification of the Data Breach

The DPO qualifies and confirms the Data Breach. It informs the persons authorised to know within COGELEC.

12.3 Establishment of Personal Data Breach Sheets and Breach Register

The DPO fills in the record and the register of Violations, if applicable, with the help of the Head of Information Systems Security (CISO).

12.4 Information to the End Customer, Data Controller

In the event of a Personal Data Breach, COGELEC undertakes, within twenty-four (24) hours after becoming aware of it (confirmed qualification), to notify the End Customer of this Breach.

At the same time, COGELEC transmits to the End Customer, an analysis including in particular:

12.5 Cooperation with the End Customer, Data Controller

COGELEC undertakes to cooperate in order to allow the End Customer to notify the Personal Data Breach to any competent supervisory authority or even to the Data Subjects in accordance with the Applicable Regulations.

13. Subsequent Subcontracting

As of the date hereof, COGELEC uses Subsequent Subcontractors for the Processing of Data entrusted to it by the End Customer. Subsequent Subcontractors are listed in Appendix 2 of this Policy.

COGELEC keeps a register of the Subsequent Subcontractors it uses, the subcontracted activities and the contracts concluded with these Subsequent Subcontractors.

In the event of the addition or change of Subsequent Subcontractors, COGELEC shall inform the End Customer in advance. The latter has a maximum period of fifteen (15) days from the date of receipt of this information to present its objections.

Objections must be notified by the End Customer to the COGELEC DPO at [email protected].

COGELEC is not required to waive a change of Subsequent Subcontractor. If following an objection from the End Customer, COGELEC does not waive the change of Subcontractor, the End Customer may terminate the Associated Services concerned without being entitled to compensation.

Subsequent Subcontractors are required to comply with the obligations hereof on behalf of and according to the instructions of the End Customer. It is COGELEC's responsibility to ensure that its Sub-Processors provide sufficient guarantees as to the implementation of appropriate technical and organizational measures so that the Processing meets the requirements of the Applicable Regulations.

If a Sub-Processor of COGELEC does not fulfil its obligations regarding the protection of Personal Data, COGELEC remains fully liable to the End Customer for its obligations.

14. Data Transfer Outside the EEA

The End Customer's Personal Data is hosted in France and is not transferred, as of the date hereof, outside the EEA.

In the event that COGELEC is required to transfer Personal Data outside the EEA to a recipient whose country, territory or sector is not the subject of an adequacy decision by the European Commission within the meaning of Article 45 of the GDPR, it undertakes to put in place appropriate safeguards within the meaning of Article 46 of the GDPR, for example by using the European Commission's standard contractual clauses for the transfer of Personal Data to a third country, unless one of the derogations permitted by Article 49 of the GDPR can apply.

COGELEC will inform the End Customer and, in the case of transfers referred to in Article 46 or the second subparagraph of Article 49 (1) of the GDPR, will make available to the End Customer a copy of the appropriate safeguards used so that the End Customer can fulfil its obligations towards the Data Subjects under Articles 13, 14 and 15 of the GDPR.

15. Impact analysis

At the request of the End Customer, COGELEC participates in any impact analysis prior to the implementation of a Processing of Personal Data by the End Customer and involving the use of the Associated Services and Management Sites provided by COGELEC.

If the End Customer wishes COGELEC to participate in carrying out an impact study, they must contact COGELEC's DPO at [email protected]. The latter will be responsible for inviting COGELEC employees authorised to participate in the planned study.

In the absence of a specific procedure proposed by the End Customer, COGELEC follows the CNIL impact assessment method. It is specified that COGELEC usually carries out its impact studies using the PIA tool proposed by the CNIL.


Appendix 1 – Summary of Technical and Organisational Safety Measures implemented by COGELEC

As part of the performance of its services, the COGELEC Group implements technical and organizational measures to ensure the confidentiality, integrity and availability of data, in accordance with the requirements of the General Data Protection Regulation (GDPR) and good security practices.

1. Organizational security

Governance

Inventory

IS Access Control

Customer/User Access Control

Supplier relations

Protection of Personal Data

2. Safety measures applicable to persons

3. Physical security measures

At the access-protected headquarters

At the host

4. Technological security measures

Security of redundant Firewalls, IDS/IPS, WAF networks

Operational

Backup


Appendix 2 – List of Subsequent Subcontractors
Identity and contact information Subcontracted role / functions / processing activities Non-EEA Data Transfer (Yes/No) In the event of data transfer, what safeguards are in place?
OVH
SAS with a capital of €10,069,020
2 rue Kellermann – 59100 Roubaix – France
RCS Lille Métropole 424 761 419
Data hosting in France – server / infrastructure maintenance No N/A
Orange (operator)
SA with a capital of €10,640,226,396
78, rue Olivier de Serres 75015 Paris
RCS Paris 380 129
SIM card provider No N/A
SFR (operator)
SA with a capital of €3,423,265,598.40
1 Square Bela Bartok 75015 Paris
RCS Paris 343 059 564
SIM card provider No N/A
Bouygues Télécom (operator)
SA with a capital of €712,588,399.56
37-39 rue Boissière 75116 Paris
RCS Paris 397 480 930
SIM card provider No N/A
Acronis International GmbH
Rheinweg 9 · 8200 Schaffhausen
Switzerland
Secondary backup in France Non DPA and contractual standard clauses have been signed in case of cross-border transfer (GDPR standard SCC)
Wasabi Technologies LCC
111 Huntington Ave, Boston, MA 02199
Storage of backups in France of data for the programming of Products Non DPA and contractual standard clauses have been signed in case of cross-border transfer (GDPR standard SCC)
eSenDex
Commify France SASU trading
9-13 rue des cuirassiers, 69003 Lyon, France
Sending SMS message to residents/users No N/A
Sinch
Sweden AB
Lindhagensgatan 74, 112 18 Stockholm, Sweden
SMS, voice, email, video tools No N/A