COGELEC: refers to the parent company COGELEC, SA with a Board of Directors, with a capital of 4,004,121.60 euros, registered with the Trade and Companies Register of LA ROCHE SUR YON, under number 433.034.782, whose registered office is located at 370 rue de Maunit - 85290 Mortagne-sur-Sèvre France. COGELEC is a French manufacturer of access control, intercom and access security solutions that markets its products and solutions under the brands Intratone®, Rozoh®, Hexact®, Kibolt®.
COGELEC Group: refers to the group of companies formed by COGELEC and its subsidiaries INTRATONE UK, INTRATONE GMBH and INTRATONE BV.
End Customer: means the legal and/or natural person who decides to install and use the Products manufactured by COGELEC and marketed either directly by the COGELEC Group or indirectly by authorized distributors/installers. The End Customer is the Data Controller (social landlord, trustee, public or tertiary institution).
Personal Data: refers to any information making it possible to directly or indirectly identify a Data Subject.
Incident: refers to any event, accidental or malicious, which affects the security of a data medium (Personal Data or not), such as a cyberattack, fire, flood, loss or theft of equipment, and which is likely to lead to a Personal Data Breach. An Incident does not always lead to such a Breach.
Data Subject: refers to any natural person whose Personal Data is processed by the End Customer, in the context of the performance of the Services.
Products: refers to all equipment manufactured by COGELEC such as intercom, access control or access security devices.
Associated Services: correspond to remote management and networking services provided by COGELEC and allowing the use of the Products sold and the management of access in the equipped premises (intercom and access control services, programming and access to the management platform and applications, license on embedded software, maintenance and deployment of computer servers, synchronization and updating of access control functional data, after-sales service and technical support, telephone support, documentation, etc.).
Sites/Management Platforms: refers to the sites allowing the End Customer to configure an intercom or access control equipment. These include www.intratone.info, www.web.hexact.fr, www.organigramme.info or www.rozoh.info.
Pseudonymisation: refers to the processing of Personal Data in such a way that it can no longer be attributed to a specific Data Subject without the use of additional information, provided that this additional information is kept separately and subject to technical and organisational measures to ensure that the Personal Data is not attributed to an identified or identifiable natural person.
Applicable Regulation: refers to Regulation No.2016/679 relating to the protection of natural persons with regard to the processing of Personal Data [or GDPR] and to the free movement of such Personal Data and Law No.78-17 of 6 January 1978 relating to data processing, files and freedoms [or LIL]. The GDPR is applicable in all territories of the European Union as well as in the territory of the UK with the UK-GDPR and the Data Protection Act 2018 (DPA Act-2018) which has benefited from an adequacy decision since 28 June 2021.
Data Controller: refers to the person (natural or legal) who, alone or jointly with others, determines the purposes of the Processing (why the data processing is implemented), as well as its means (how it is implemented).
Data Processor/Subcontractor: means the natural or legal person who Processes in the name and on behalf of the Controller of Personal Data.
Processing: refers to a set of operations carried out on Personal Data, such as collection, organization, recording, access, playback, storage, backup, restoration, restitution, destruction.
Personal Data Breach or Breach: means a breach of security resulting in the destruction, loss, alteration, unauthorized disclosure or illegal or accidental access to Personal Data transmitted, stored or Processed.
COGELEC is a French manufacturer of wireless intercoms, access control and access security solutions, present in several countries in Europe.
The COGELEC Group markets its products and solutions mainly to social landlords, trustees, distributors and installers who wish to set up access control systems for the residential sector. It also markets them in the tertiary sector, to companies and communities seeking to secure access to their premises.
Aware of the importance of ensuring the security and confidentiality of the Personal Data of Data Subjects on behalf of the End Customer, the COGELEC Group makes strong commitments to them.
Its approach falls within the framework of the Applicable Regulations, as well as the doctrine of the European Data Protection Board (EDPS) and the national competent authorities specific to each country where the Data Subjects are located.
The commitments of the COGELEC Group could evolve according to the legal and regulatory context, the decisions of the competent judges and the doctrine of the EDPS and the competent authorities, in particular the CNIL in France, which is the lead authority for the COGELEC Group.
| Countries concerned | Competent authorities |
|---|---|
| France | Commission Nationale de l'Informatique et des Libertés (CNIL) |
| United Kingdom | Information Commissioner's Office (ICO) |
| Germany | Bundesbeauftragte für den Datenschutz und die Informationsfreiheit = At federal level, it is the Federal Commissioner for Data Protection and Freedom of Information (BfDI) |
| Netherlands | Autoriteit Persoonsgegevens (AP) Dutch Data Protection Authority |
| Belgium | Data Protection Authority/Gegevensbeschermingsautoriteit |
| Luxembourg | National Commission for Data Protection (CNPD) |
The Policy has no contractual value. It recalls the legal obligations and commitments to which the COGELEC Group companies and the End Customer are bound. It does not bind the Data Subjects and does not impose obligations on them but grants them rights.
The purpose of the Policy is to centralize in a single document, in a clear and concise manner, information on the measures and commitments taken by the COGELEC Group, when it Processes the Data Subjects' Data in the name and on behalf of the Data Controller.
The Policy applies to the Processing of Personal Data carried out by the Data Controller when using the Associated Services and especially the Management Platforms hosted and maintained by COGELEC. It therefore applies to the Processing established by the COGELEC Group as a Data Processor.
Conversely, the Policy does not apply to Processing carried out by the COGELEC Group when it acts as Data Controller, namely in its commercial relations with its customers (a dedicated policy is available).
The Policy applies to the COGELEC Group and the End Customer insofar as they are established in the territory of the European Union or the EEA, the United Kingdom, Switzerland and Monaco and Process Data Subject Data which are also located in these territories.
As part of their relations, the COGELEC Group and the End Customer undertake to comply with the Applicable Regulations according to its territorial location.
The End Customer is the Data Controller and the COGELEC Group acts as Data Processor. The End Customer expressly authorises the COGELEC Group, acting as Data Processor, to Process in its name and on its behalf the Personal Data necessary for the performance of the Associated Services.
COGELEC has appointed a Data Protection Officer ("DPO"). The DPO centralises data protection management for all COGELEC Group companies in accordance with Art. 37.2 of the GDPR and is assisted, where appropriate, by specialist lawyers in each country where the COGELEC Group is represented.
| Identity | SPARLANN Contact Information |
|---|---|
| Sarah BENGUIGUI | [email protected] |
The COGELEC Group undertakes to:
The Data Controller undertakes to:
The Policy relates only to Processing implemented by the Data Controller and subcontracted to the COGELEC Group.
| Nature of operations carried out on Personal Data | Transmission to the programming service and configuration of the equipment (if the service is ordered), provision of an online Management Platform, hosting of Personal Data and assistance to the End Customer. |
|---|---|
| Processing carried out | Access, playback, collection, integration, organization, storage, recording, backup, modification, extraction, restoration, restitution, destruction, erasure. |
| Duration of the Processing | As long as the Data Controller wishes to benefit from the Associated Services and until the end of the reversibility operations. |
| Purpose(s) of the Processing pursued by the Data Controller | Implementation of devices to control and secure access to buildings/sites equipped by the Data Controller. |
| Personal Data Processed |
Residents: occupants, tenants, owners whether private or professional, employees, agents – Users = employees, agents, employees Directly collected data: Surname, first name, home or work address, telephone numbers, apartment number, badge number. Automatic data collection: IP address of equipment, intercom and mobile brand and model, logs of connection to the Management Site/mobile application, events: date and time of opening of the door (badges or audio/video connections) Users of the Management Sites designated by the End Customer: Surname, first name, email, position, IP or login credentials, cookie ID |
Unless otherwise instructed by the Data Controller, Personal Data is kept by COGELEC under the conditions and in the manner described below.
In principle, Personal Data is kept for as long as the End Customer wishes to benefit from the Associated Services.
Thus, as long as the Personal Data of the resident or user benefiting from the access control device (intercom, badge, etc.) are processed by the End Customer through COGELEC's Management Platforms, and are not deleted by the End Customer, the Data are kept on COGELEC's servers.
As part of the "turnkey" Service, the COGELEC Group proposes to the End Customer to ensure in its name and on its behalf the programming of the Products and Personal Data of residents/users via the Management Site, to respond to a request for assistance from the End Customer and identify potential input errors.
In the context of this Associated Service, the files are kept for the time necessary for the operations of configuring the Products. Following the programming operations, the files are kept for an additional three (3) months for the End Customer's assistance. They are then deleted.
In residential configurations, "events" (access logs including, in particular, the equipment used, the action performed, and the date and time of access) are, by default, not accessible in a nominative manner to the Data Controller and/or the manager of the Management Platform.
In accordance with CNIL recommendations relating to access control systems in collective residential buildings, the events visible from the Management Platform are anonymised in order to prevent any use of the system for monitoring residents.
The Data Controller configures the Management Platform itself and remains solely responsible for the settings it chooses to activate and the purposes pursued in this context.
Depending on the purposes pursued, COGELEC may act either as a data controller or as a data processor:
No other processing or operation is carried out on the events. At the end of the three (3) month retention period, the events are anonymised. The anonymisation process consists of permanently deleting the link between the badge identifier and the associated events (door used, action performed, timestamp). This process is irreversible.
Personal Data may be deleted by the End Customer directly on the Management Site, for example, when a Data Subject leaves a residence or its functions authorizing it to access a building or an equipped site.
Personal Data may also be deleted at the request of the Data Subject in the context of the implementation of Article 17 of the GDPR, subject to compliance with the applicable conditions. Such a request for deletion shall be made to the End Customer.
At the end of the Associated Services and at any time, upon the written and prior request of the End Customer, the Data shall be returned to the End Customer within an appropriate period, not exceeding thirty (30) working days, from the receipt of the request by COGELEC. In agreement with the End Customer, this period may be extended.
The Personal Data will be returned to the End Customer in the same format as that used by the Data Controller to make the Personal Data available to COGELEC or, failing that, in the available export(s), and at no additional cost to the latter. To date, the available format is Excel, ".xlsx" or ".xls".
The return may be the subject of a report signed between the Parties, at the request of the Data Controller.
COGELEC permanently destroys, three (3) months after programming, the copies of the Personal Data held in its systems, unless the legislation imposed on COGELEC prevents it from returning or destroying all or part of the Personal Data. COGELEC may provide proof of this to the End Customer simultaneously with the signing of the return report.
COGELEC declares to keep in writing a register of all categories of Processing activities carried out in the name and on behalf of the End Customer, Data Controller, including:
The COGELEC Group undertakes to assist and collaborate with the End Customer in order to enable the latter to comply with its obligations under the Applicable Regulations.
The Data Controller is solely responsible for managing the requests of the Data Subjects.
The COGELEC Group undertakes, within a period not exceeding ten (10) days and without directly acceding to the request of the Data Subjects, to cooperate with the Data Controller in the event that the latter is requested in the context of the performance of its obligation to respond to requests for the exercise of the rights of the Data Subjects (access, rectification, erasure, opposition, portability, etc.) to:
If the COGELEC Group considers that an instruction constitutes a violation of the Applicable Regulations, any other provision of Union law or the law of the Member States relating to the protection of Personal Data, it shall immediately inform the End Customer. However, the COGELEC Group is not required to check whether any instruction given by the Data Controller complies with the Applicable Regulations.
The COGELEC Group may not, under any circumstances, be held liable in the event of unlawful instructions from the End Customer, constituting a violation of the Applicable Regulations.
Taking into account the state of knowledge, the implementation costs, the nature, scope, context and purposes of the Processing as well as the risks to the rights and freedoms of Data Subjects, the COGELEC Group implements the appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
For the choice of measures, COGELEC refers in particular to the state of the art and the recommendations of the competent authorities such as the CNIL or the ANSSI.
All the measures taken by the COGELEC Group to guarantee the confidentiality, availability, integrity and traceability of Personal Data are described in the Data Processor's "Security Assurance Plan" available on request. A summary of this plan is attached to this policy.
The COGELEC Group may modify the security measures at any time, without having to inform the End Customer, the Data Controller, in advance and update its information in this document.
The End Customer is required to take all necessary precautions, with regard to the nature of the Personal Data and the risks presented by the Processing, to preserve the security of the Personal Data and, in particular, to prevent it from being distorted, damaged or accessed by unauthorised third parties.
Thus, the End Customer undertakes to take all necessary protective measures to ensure:
In summary, in the event that an Incident has an impact (destruction, loss, alteration, unauthorized access or disclosure of Personal Data, etc.) on the End Customer's Personal Data processed by COGELEC, the procedure followed is described below.
The DPO checks the documents transmitted, the data impacted and in particular whether the End Customer's Personal Data has been affected.
The DPO qualifies and confirms the Data Breach. It informs the persons authorised to know within COGELEC.
The DPO fills in the record and the register of Violations, if applicable, with the help of the Head of Information Systems Security (CISO).
In the event of a Personal Data Breach, COGELEC undertakes, within twenty-four (24) hours after becoming aware of it (confirmed qualification), to notify the End Customer of this Breach.
At the same time, COGELEC transmits to the End Customer, an analysis including in particular:
COGELEC undertakes to cooperate in order to allow the End Customer to notify the Personal Data Breach to any competent supervisory authority or even to the Data Subjects in accordance with the Applicable Regulations.
As of the date hereof, COGELEC uses Subsequent Subcontractors for the Processing of Data entrusted to it by the End Customer. Subsequent Subcontractors are listed in Appendix 2 of this Policy.
COGELEC keeps a register of the Subsequent Subcontractors it uses, the subcontracted activities and the contracts concluded with these Subsequent Subcontractors.
In the event of the addition or change of Subsequent Subcontractors, COGELEC shall inform the End Customer in advance. The latter has a maximum period of fifteen (15) days from the date of receipt of this information to present its objections.
Objections must be notified by the End Customer to the COGELEC DPO at [email protected].
COGELEC is not required to waive a change of Subsequent Subcontractor. If following an objection from the End Customer, COGELEC does not waive the change of Subcontractor, the End Customer may terminate the Associated Services concerned without being entitled to compensation.
Subsequent Subcontractors are required to comply with the obligations hereof on behalf of and according to the instructions of the End Customer. It is COGELEC's responsibility to ensure that its Sub-Processors provide sufficient guarantees as to the implementation of appropriate technical and organizational measures so that the Processing meets the requirements of the Applicable Regulations.
If a Sub-Processor of COGELEC does not fulfil its obligations regarding the protection of Personal Data, COGELEC remains fully liable to the End Customer for its obligations.
The End Customer's Personal Data is hosted in France and is not transferred, as of the date hereof, outside the EEA.
In the event that COGELEC is required to transfer Personal Data outside the EEA to a recipient whose country, territory or sector is not the subject of an adequacy decision by the European Commission within the meaning of Article 45 of the GDPR, it undertakes to put in place appropriate safeguards within the meaning of Article 46 of the GDPR, for example by using the European Commission's standard contractual clauses for the transfer of Personal Data to a third country, unless one of the derogations permitted by Article 49 of the GDPR can apply.
COGELEC will inform the End Customer and, in the case of transfers referred to in Article 46 or the second subparagraph of Article 49 (1) of the GDPR, will make available to the End Customer a copy of the appropriate safeguards used so that the End Customer can fulfil its obligations towards the Data Subjects under Articles 13, 14 and 15 of the GDPR.
At the request of the End Customer, COGELEC participates in any impact analysis prior to the implementation of a Processing of Personal Data by the End Customer and involving the use of the Associated Services and Management Sites provided by COGELEC.
If the End Customer wishes COGELEC to participate in carrying out an impact study, they must contact COGELEC's DPO at [email protected]. The latter will be responsible for inviting COGELEC employees authorised to participate in the planned study.
In the absence of a specific procedure proposed by the End Customer, COGELEC follows the CNIL impact assessment method. It is specified that COGELEC usually carries out its impact studies using the PIA tool proposed by the CNIL.
As part of the performance of its services, the COGELEC Group implements technical and organizational measures to ensure the confidentiality, integrity and availability of data, in accordance with the requirements of the General Data Protection Regulation (GDPR) and good security practices.
Governance
Inventory
IS Access Control
Customer/User Access Control
Supplier relations
Protection of Personal Data
At the access-protected headquarters
At the host
Security of redundant Firewalls, IDS/IPS, WAF networks
Operational
Backup
| Identity and contact information | Subcontracted role / functions / processing activities | Non-EEA Data Transfer (Yes/No) | In the event of data transfer, what safeguards are in place? |
|---|---|---|---|
| OVH SAS with a capital of €10,069,020 2 rue Kellermann – 59100 Roubaix – France RCS Lille Métropole 424 761 419 |
Data hosting in France – server / infrastructure maintenance | No | N/A |
| Orange (operator) SA with a capital of €10,640,226,396 78, rue Olivier de Serres 75015 Paris RCS Paris 380 129 |
SIM card provider | No | N/A |
| SFR (operator) SA with a capital of €3,423,265,598.40 1 Square Bela Bartok 75015 Paris RCS Paris 343 059 564 |
SIM card provider | No | N/A |
| Bouygues Télécom (operator) SA with a capital of €712,588,399.56 37-39 rue Boissière 75116 Paris RCS Paris 397 480 930 |
SIM card provider | No | N/A |
| Acronis International GmbH Rheinweg 9 · 8200 Schaffhausen Switzerland |
Secondary backup in France | Non | DPA and contractual standard clauses have been signed in case of cross-border transfer (GDPR standard SCC) |
| Wasabi Technologies LCC 111 Huntington Ave, Boston, MA 02199 |
Storage of backups in France of data for the programming of Products | Non | DPA and contractual standard clauses have been signed in case of cross-border transfer (GDPR standard SCC) |
| eSenDex Commify France SASU trading 9-13 rue des cuirassiers, 69003 Lyon, France |
Sending SMS message to residents/users | No | N/A |
| Sinch Sweden AB Lindhagensgatan 74, 112 18 Stockholm, Sweden |
SMS, voice, email, video tools | No | N/A |