Hit by a cyberattack?Need to secure your IT effectively?
IT1 Connect
PERSONAL DATA

Privacy Policy

This is a courtesy translation. Only the French version of this document is legally binding, and French law applies. Should the two versions differ, the French one prevails: read the French version.

The purpose of this privacy policy is to inform visitors and users of www.it1-connect.com how their personal data is protected, in accordance with French Act no. 78-17 of 6 January 1978 on information technology, data files and civil liberties (as amended by the Act of 20 June 2018), implementing Decree no. 2019-536 of 29 May 2019, and Regulation no. 2016-679 of 27 April 2016 (GDPR).

Data controller and contact

The data controller is OUSTAOU CONNECT (trading as IT1 Connect), 1 Rue de l’Égalité, 83870 Signes, registered with the Toulon Trade and Companies Register under number 852 038 868.

Data Protection Officer (DPO): Franck Sztendera. Contact: [email protected].

Purposes and legal bases

In accordance with the GDPR (EU Regulation 2016/679) and the amended French Data Protection Act, IT1 Connect collects and processes your personal data for the following purposes, each resting on a legal basis:

  • Handling contact and quote requests: steps taken prior to entering into a contract, and legitimate interests.
  • Handling orders and the customer relationship: performance of the contract.
  • Invoicing and accounting: legal obligation.
  • Verifying the identity and the status of business and public authority customers before an order is placed (fraud prevention, application of the pricing reserved for businesses and public authorities): steps taken prior to entering into a contract, and legitimate interests.
  • Assessing the financial standing of businesses applying for deferred payment (URSSAF vigilance certificate, latest annual accounts): legitimate interests (establishing solvency before granting a payment term and preventing unpaid invoices).
  • Commercial prospecting aimed at business customers: legitimate interests; for individuals and for the newsletter: consent.
  • Site security and improvement: legitimate interests.

Data collected

The data collected is: surname, first name, address, e-mail, telephone, billing and delivery details.

As part of the document check carried out before an order is placed, which applies to business and public authority accounts, the following is also collected, depending on the account type: KBIS extract (French company registration certificate), identity document of the company manager or of the signatory, SIRET number, and appointment order or signature delegation. Businesses applying for deferred payment additionally provide a URSSAF vigilance certificate and their latest annual accounts. No supporting document is collected for an individual account. These processing operations are detailed in the “Document check on customer accounts” section.

Document check on customer accounts

Before any order is placed, business and public authority accounts are subject to a check intended to confirm the identity and the status (business or public authority) of the account holder. The individual account is subject to no document check and to no collection of supporting documents. Business and public authority customers upload their supporting documents from the “My application” area of the shop.

Documents processed, by account type

  • Business: KBIS extract, identity document of the company manager, company name and SIRET number;
  • Public authority: SIRET number, appointment order or signature delegation, identity document of the signatory;
  • Business applying for deferred payment (optional step): URSSAF vigilance certificate and latest annual accounts.

Legal basis: steps taken prior to entering into a contract (article 6.1.b of the GDPR) and the legitimate interest in preventing fraud and in reserving certain pricing terms (article 6.1.f of the GDPR). For the review of deferred payment applications (URSSAF certificate and annual accounts), processing rests on the legitimate interest of IT1 Connect in establishing customer solvency before granting a payment term and in preventing unpaid invoices. Collection is limited to what is strictly necessary for the check.

Recipients: only authorised IT1 Connect staff in charge of the check have access to these documents, and every consultation is logged. These documents are neither transferred nor disclosed outside the European Union.

Retention period: supporting documents are deleted as soon as the account is approved or, for documents relating to deferred payment (URSSAF certificate, annual accounts), as soon as that access is approved; applications that are not approved are purged automatically after 14 days; all documents are erased if the account is deleted.

Security: documents are stored outside the public web directory, under random file names, and encrypted at rest (AES-256-GCM encryption). Access is restricted and traced.

Recipients

Your data is intended for authorised internal departments of IT1 Connect and, where applicable, for our processors: payment provider, carrier, hosting provider, software publishers. No data is sold or disclosed to third parties for commercial purposes.

Transfers outside the European Union

The data processed by IT1 Connect is hosted in France and is not transferred outside the European Union.

Processing carried out by our payment providers is an exception: when a payment is made, PayPal and our payment provider act as independent data controllers and may process some of your data under their own privacy policies, where applicable outside the European Union. We invite you to consult those policies for the safeguards that apply.

Retention periods

Prospect and customer data: 3 years from the last contact.

Accounting records and invoices: 10 years (legal obligation).

Beyond those periods, data is deleted or anonymised.

Your rights

You have a right of access, rectification, erasure, restriction, objection and portability, the right to withdraw your consent at any time, and the right to give instructions on what happens to your data after your death. To exercise them, contact us by e-mail: [email protected]. You may also lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr).

Cookies

The website www.it1-connect.com and the online shop shop.it1-connect.com use cookies that are necessary for them to work, for your purchasing journey and for payment security (in particular through PrestaShop and PayPal). Non-essential cookies, where applicable, are only placed with your consent.

For further information, see our cookie policy.

Security of data and transactions

As a specialist in IT and cybersecurity solutions, IT1 Connect places the protection of your data at the heart of its priorities. We implement rigorous technical and organisational measures to guarantee the integrity, confidentiality and availability of your information.

Protecting the site and the exchanges

  • SSL/TLS encryption: the whole site is secured with HTTPS, and all data exchanged between your browser and our servers is encrypted.
  • Up-to-date technologies: we use recent technologies and keep them constantly updated in order to fix any vulnerabilities.
  • Active monitoring: our servers are continuously monitored to detect and prevent intrusion or suspicious activity.
  • Web application firewall (WAF): we filter incoming traffic to block malicious requests (brute force, injections, denial of service).

Payment security

  • Payments made in our shop go exclusively through the secure interface of our payment provider.
  • No banking data stored: at no point does IT1 Connect have access to your banking details, and no card data is stored on our servers.

Restricted access

Only authorised members of the IT1 Connect team have access to the data collected, through strong authentication protocols.

Hyperlinks

The site may contain links to other websites. IT1 Connect accepts no liability for the content of those third-party sites, over which it has no control.

Governing law

This site is governed by French law.

Any dispute relating to the use of www.it1-connect.com will be brought before the courts having jurisdiction over the registered office of IT1 Connect.