Personal Data Protection Policy

Personal Data Protection Policy

The French Agency for Energy Management and Ecological Transition (“ADEME”), a public industrial and commercial institution whose registered office is located at 20, avenue du Grésillé 49000 Angers, attaches great importance to the protection of Personal Data which it is led to collect and process as data controller within the framework of its activity.

The collection and Processing of Personal Data by ADEME within the framework of its activity and the use of its products and services, information and communication Internet sites, databases, web applications – which may require the creation of an account and enable user/application interaction –, and mobile applications, are thus governed by this data protection policy (hereinafter referred to as the “Policy”).

All Processing of Personal Data implemented within the framework of the accessible Services complies with the applicable regulations with regard to the protection of personal data and in particular with the provisions of the French “Data Protection and Civil Liberties” Act of 6 January 1978 as amended, and the General Data Protection Regulation (EU Regulation 2016/679) (“GDPR”).      
In order to ensure proper application of these rules, ADEME has appointed a Data Protection Officer who is the primary point of contact with the Commission nationale de l’informatique et des libertés (the “CNIL”, French National Commission for Data Protection and Civil Liberties).      
ADEME also implements appropriate internal procedures to raise awareness among its employees and ensure compliance with these rules within its organisation.

The purpose of this Policy is to inform Data Subjects, as defined below, with regard to: 

  • the manner in which ADEME processes the Personal Data, as defined below, that it collects, which the Data Subjects, as defined below, provide with their consent or on any other legal basis in order to enable the provision of ADEME’s Products and Services in particular;
  • the Data Subjects’ rights;
  • any beneficiaries of data transfers. 

Data Subjects should therefore read this Policy carefully in order to inform themselves and understand ADEME’s practices concerning its Processing of Personal Data. 

1. Definitions

Capitalised terms are defined as follows. Terms have the same definition whether used in the singular or the plural. 

  • «Personal Data» means any information relating to an identified or identifiable natural person. 
  • «Data Subject(s)» means a natural person who can be identified, directly or indirectly, in particular by means of reference to an identifier, such as a surname, identification number, location data, online identifier, or one or several elements specific to their physical, physiological, genetic, mental, economic, cultural or social identity. 

  •  «Products» means ADEME products.
  • «Data Controller» means ADEME which is the legal entity which, alone or jointly with others, determines the aims and means of the  processing.
  • «Services» means the services provided by ADEME.
  • «Websites» means the whole of the web pages and resources accessible on the Internet.
  • «Processing» means any operation or any set of operations performed on personal data or sets of personal data, whether or not by means of automated processes, such as collection, recording, organisation, structuring, retention, adaptation or modification, retrieval, consultation, use, communication via transmission, dissemination or any other form of making available, alignment or interconnection, limitation, deletion or destruction. 

2. What are ADEME’s undertakings with regard to the protection of  Personal Data? 

ADEME undertakes to guarantee a high level of protection of the Personal Data of the Data Subjects who use its Websites and other Products and Services and of any other person whose Personal Data it processes.

ADEME undertakes to comply with the regulations (in particular Articles 5 and 6 of the GDPR) applicable to all Processing of Personal Data that it implements. More specifically, ADEME undertakes in particular to comply with the following principles: 

  • Personal Data is processed in a lawful, fair and transparent manner (lawfulness, fairness, transparency);
  • Personal Data is collected for specified, explicit and legitimate purposes, and is not subsequently processed in a manner incompatible with these purposes (purpose limitation);
  • Personal Data is stored in an appropriate and relevant manner and is limited to what is necessary in view of the purposes for which it is processed (data minimisation);
  • the Personal Data is accurate, and kept up to date, and all reasonable measures are taken to ensure that inaccurate data, in view of the purposes for which it is processed, is deleted or corrected without delay (accuracy). 

ADEME implements appropriate technical and organisational measures to guarantee a level of security appropriate to the risk inherent to its Processing operations, to meet regulatory requirements and to protect Data Subjects’ rights and Personal Data from the very design stage of the Processing operations.

Moreover, ADEME contractually imposes the same level of protection of Personal Data on its subcontractors (service providers, suppliers, etc.).


Finally ADEME undertakes to comply with any other principle required in view of applicable regulations regarding the protection of Personal Data, and more specifically concerning the rights given to Data Subjects, the lengths of periods of retention of Personal Data and obligations relating to cross-border transfers of Personal Data. 

3. What are the categories of Personal Data?

Within the framework of the use of its products, services and Websites, several types of Personal Data may be collected by ADEME.

The data collected principally corresponds to the following categories: 

  • identification data: surname, first name, pseudonym, date of birth; contact details  
  • data: landline or mobile telephone number, postal address, and e-mail address. 

4. Means of collecting Personal Data

Data Subjects may communicate their Personal Data to ADEME by various means, in particular on the Websites when browsing the Internet and through the Products and Services, by filling in various collection forms, when subscribing to a newsletter, creating an account, or submitting an application, at the time of any contact with ADEME and at the time of any other transmission of Personal Data in other circumstances. 

5. Purposes of processing and legal basis

The purposes of the Processing of Personal Data carried out by ADEME are based on the following legal foundations: contractual performance, the Data Subjects’ consent, ADEME’s legal and regulatory obligations, its legitimate interest and its mission in the public interest

The purposes associated with each legal basis are listed below: 

  • On the basis of the performance of pre-contractual measures taken at the Data Subjects’ request and/or the performance of the contract the latter have entered into, ADEME implements Processing for the following purposes:
    • management of the relationship between Website users and ADEME, including in particular:
      • the creation of user accounts;
      • use of websites and services;
      • management of communications and follow up of exchanges with users.
  • On the basis of the Data Subjects’ consent, ADEME implements Processing for the following purposes:
    • provision of personalised Services, such as announcements, newsletters, training courses, etc.;
    • provision of optional Services such as interactive discussion forums and chats;
    • management of user participation in games and competitions;
    • management of cookies subject to consent.
  • On the basis of compliance with its legal and regulatory obligations, ADEME implements Processing in pursuit of the following purposes:
    • development of Products and Services enabling facilitation of the completion of the administrative formalities necessary for processing requests from Internet users and users;
    • management of responses to official requests from public and judicial authorities authorised to this end;
    • compliance with the regulations applicable to our activity;
    • management of requests for the exercise of rights.
  • On the basis of its legitimate interests, ADEME implements Processing in pursuit of the following purposes:
    • development and improvement of new Products and Services and offers of Products and Services to Internet users and/or for the benefit of the public;
    • combating fraud and abuse, including management of the consequences of such fraud and abuse;
    • Management of security breaches and of any problems of a technical order encountered by Products and Services;
    • completion of commercial canvassing operations aimed at professionals;
    • management of customers and employees within a group of companies for reasons of internal administrative management;
    • management of requests for information and complaints from users;
    • Establishment of any means of evidence necessary for the defence of ADEME’s rights;
    • management of cookies not subject to consent.
  • On the basis of its mission in the public interest, ADEME implements Processing in pursuit of the following purposes:
    • Management of requests for aid enabling facilitation of the completion of the administrative formalities necessary for the processing of requests from users;
    • management of communications and follow up of exchanges with users;
    • compliance with the regulations applicable to our activity. 

6. For how long is personal data retained?

ADEME undertakes to retain the Data Subjects’ Personal Data for a period not exceeding that required to fulfil the purposes for which it is processed, plus the statutory limitation period. Moreover, ADEME shall retain the Data Subjects’ Personal Data in accordance with the retention times imposed by the applicable laws in force, where applicable.

More specifically, ADEME organises its data retention policy as follows: 

PURPOSES  RETENTION PERIODS 
Management of the relationship between Website users and ADEME 

The data is retained throughout the period of the contractual relationship: the lifespan of the user account or last incoming contact (login or modification of the personal space), plus the time until expiry of the statutory limitation period.

The statutory limitation period under ordinary law in civil and commercial matters is five (5) years from the end of the contract. 

Provision of personalised Services           
  
The data is retained for three (3) years from the last incoming contact 
Provision of optional Services  The data is retained for three (3) years from the last incoming contact 
Management of user participation in games and competitions  The data is retained for three (3) years from the last incoming contact 
Development of Products and Services enabling facilitation of the completion of the administrative formalities necessary for processing requests from Internet users and users 

The data is retained throughout the period for completion of the administrative formalities, plus the time until expiry of the statutory limitation period.

The statutory limitation period under ordinary law in civil and commercial matters is five (5) years from the end of the contract. 

Management of responses to official requests from public and judicial authorities authorised to this end  The data is retained throughout the authorities’ investigation. 
Management of requests for the exercise of rights  The data is retained for one (1) or six (6) years, depending on the right exercised. 
Combating fraud and abuse 

Data may be retained for up to twelve (12) months from the date of issue of alerts before being classified.

Alerts classified as irrelevant or not classified at the end of the twelve (12) month period are deleted.

Classified alerts are retained for a maximum period of five (5) years from the closure of the fraud case.           
For persons included on a list of individuals proven guilty of fraud, data concerning them is deleted after a period of five (5) years from the date of inclusion on this list.

If legal proceedings have been brought, the data shall be retained until the end of the legal proceedings, plus the time until expiry of the statutory limitation period.

The statutory limitation period under ordinary law in civil and commercial matters is five (5) years from the end of the contract. 

Management of security breaches  Computer records are kept for thirteen (13) months. 
Completion of commercial canvassing operations aimed at professionals  The data is retained for three (3) years from the last incoming contact. 
Management of customers and employees within a group of companies for reasons of internal administrative management 

The data is retained throughout the period of the contractual relationship, plus the time until expiry of the statutory limitation period.

The statutory limitation period under ordinary law in civil and commercial matters is five (5) years from the end of the contract. 

Management of requests for information and complaints from users 

In case of contractual relationship with ADEME, the data is retained throughout the period of the contractual relationship, plus the time until expiry of the statutory limitation period.

The statutory limitation period under ordinary law in civil and commercial matters is five (5) years from the end of the contract.

In the absence of a contractual relationship with ADEME, the data is retained for three (3) years from the last incoming contact. 

Establishment of any means of evidence necessary for the defence of ADEME’s rights 

In case of contractual relationship with ADEME, the data is retained throughout the period of the contractual relationship, plus the time until expiry of the statutory limitation period.

The statutory limitation period under ordinary law in civil and commercial matters is five (5) years from the end of the contract.

In the absence of a contractual relationship with ADEME, the data is retained for three (3) years from the last incoming contact. 

Cookie management  Your cookie preferences are stored for 6 months. Data collected by means of cookies is retained for 25 months. 

 

7. Who may access the Data Subjects’ Personal Data?

Recipients of Data Subjects’ Personal Data

Data collected via ADEME’s Websites, Products and Services or by any other means may be communicated to ADEME’s authorised staff, its partners and service providers within the framework of the performance of all or part of their services. ADEME recalls that, within this framework, its partners and service providers are contractually required to put in place strict confidentiality and data protection measures. Furthermore, ADEME may be required to provide personal information to authorised French and foreign public authorities. 

Transfers of data outside of the European Union

Certain recipients mentioned above may be based outside of the European Union and may have access to all or part of the personal information collected by ADEME due to specific legal authorisation.

Within this framework, ADEME undertakes to guarantee the protection of Data Subjects’ Personal Data in accordance with the strictest rules, in particular via the signature, on a case-by-case basis, of contractual clauses based on the European Commission model, or any other mechanism compliant with the GDPR, whenever the Data Subjects’ Personal Data is processed by a service provider outside of the European Economic Area, whose country is not considered by the European Commission to provide an adequate level of protection.

In any case, ADEME undertakes to inform Data Subjects in advance in the case transfers of data outside of the European Union. 

8. How are Data Subjects’ acknowledged rights exercised?

In accordance with the GDPR, Data Subjects may, at any time, exercise their rights of access, correction and deletion of data concerning them, as well as their rights to limit and oppose the Processing and portability of their Personal Data.

Furthermore, when the Processing of Personal Data implemented by ADEME is based on the Data Subjects’ consent, the latter may withdraw this consent at any time. ADEME will then cease to process the Data Subjects’ Personal Data without the calling into question of previous operations for which the Data Subjects had given their consent.      
Moreover, Data Subjects are entitled to bestow the legal right to define post-mortem directives concerning the retention, deletion and communication of their Personal Data, to a trusted, certified third party entrusted with ensuring compliance with their wishes, in accordance with the requirements of the applicable legal framework.

Moreover, any person who was a minor at the time of collection of their Personal Data can obtain the deletion thereof as quickly as possible. 

Data subjects may request to exercise their right to oppose to the Processing of Personal Data concerning them for reasons relating to their particular situation, when the Processing is based on ADEME’s legitimate interest. This right of opposition also applies to profiling.

If such a right of opposition is exercised, ADEME will cease processing except where there are legitimate and compelling reasons for the Processing that override the Data Subjects’ interests, rights and freedoms, or for the establishment of facts, and the exercise or defence of rights in court.

Data Subjects may also oppose any processing connected with canvassing without it being necessary to invoke reasons relating to their particular situation. 

As part of the right of access, ADEME may ask the Data Subjects to pay a reasonable fee based on administrative costs for any further copy of the data in addition to that handed over.

These rights may be exercised by postal letter to the following address:      
ADEME      
Délégué à la Protection des Données/Data Protection Officer 20, avenue du Grésillé — BP 90406 - 49004 Angers Cedex 01 or by E-mail to the following address: [email protected]  

In this regard, Data Subjects are kindly asked to accompany requests with the information required for their identification (surname, first name, e-mail address), together with any other information required to confirm their identity.

For certain specific Services, these rights may be exercised directly online (management of your user account, management of your subscriptions to newsletters, news, etc.).

In case of violation of the applicable regulations with regard to the protection of Personal Data, Data Subjects also have the right to lodge a claim with the French Data Protection Authority (Commission nationale de l’informatique et des libertés) in France (3 place de Fontenoy - TSA 80715 - 75334 Paris cedex 07; tel.: 01 53 73 22 22), without prejudice to any other administrative or judicial remedy. 

9. IT security / ensuring security of transactions

ADEME implements all useful technical and organisational measures, in the light of the nature, scope and context of Personal Data that you pass on to us and the risks involved in the Processing thereof, in order to preserve the security of your Personal Data and, in particular, to prevent any destruction, loss, modification, disclosure, intrusion or unauthorised access to this data, whether accidentally or illegally.

The security and confidentiality of Personal Data depend on everyone’s good practices. For this reason Data Subjects are asked not to disclose their passwords to third parties, to systematically log out of their profile and corporate account (particularly in case of linked accounts) and to close their browser window at the end of their work session, especially if they are accessing the Internet from an IT station shared with other people. 

10. Personal data concerning minors

ADEME does not collect or process Personal Data concerning children under 16 years of age without prior agreement from the child’s parents or guardians.

If Personal Data concerning children is collected via ADEME’s Website and/or via the Services or Products, the parents or guardians are entitled to oppose this by contacting ADEME at the address indicated above.

Moreover, as set out above, children who are minors at the time of collection of their Personal Data can obtain the deletion thereof in the shortest possible period. 

11. Links to access other websites

On various pages of ADEME’s Websites it is possible to click to access other companies’ websites. ADEME advises you to read the policy of these sites concerning the Processing and protection of Personal Data, since the conditions on these sites may differ from those applicable on the Websites of ADEME, and the latter shall not in any case whatsoever be liable for Processing of Personal Data by these other Internet sites. 

12. Modifications

ADEME reserves the right to adapt this Policy.

If ADEME makes any changes to this Policy, it will publish the new version in the relevant media and update the “last update” date shown at the top of this Policy.

ADEME therefore invites you to regularly consult the relevant media where the Policy is published.   

 

 

Page top