Free live corrected case study webinar with an ex-consultant McKinsey Paris And an ex-consultant BCG Paris. Limited to 100 seats!

Confidentiality policy

Last updated: July 26, 2022

ARTICLE 1: PREAMBLE

This privacy policy applies to the site:

‍The purpose of this privacy policy is to explain to users of the site:
- The way in which their personal data is collected and processed. Any data that is likely to identify a user should be considered personal data. These include the first and last name, age, postal address, email address, location of the user or even his IP address
- What are the rights of users concerning this data
- Who is responsible for processing the personal data collected and processed
- To whom is this data transmitted
- Possibly, the site's policy regarding “cookie” files. This privacy policy complements the legal notices And the General conditions of use that users can see in the footers.

ARTICLE 2: GENERAL PRINCIPLES FOR DATA COLLECTION AND PROCESSING

In accordance with the provisions of article 5 of European Regulation 2016/679, the collection and processing of data from users of the site respect the following principles:
- Lawfulness, loyalty and transparency: data can only be collected and processed with the consent of the user who owns the data. Each time personal data is collected, the user will be informed that his data is collected, and for what reasons his data is collected.
- Limited purposes: the collection and processing of data are carried out to meet one or more objectives determined in these general conditions of use
- Minimization of data collection and processing: only the data necessary for the proper execution of the objectives pursued by the site are collected
- Retention of data reduced over time: the data is kept for a limited period of time, of which the user is informed. If the retention period cannot be communicated to the user; Integrity and confidentiality of the data collected and processed: the data controller undertakes to guarantee the integrity and confidentiality of the data collected.

In order to be lawful, and in accordance with the requirements of article 6 of European Regulation 2016/679, the collection and processing of personal data may only take place if they comply with at least one of the conditions listed below:
- The user has expressly consented to the treatment
- The treatment is necessary for the proper execution of a contract
- The treatment meets a legal obligation
- The treatment is explained by a necessity linked to the protection of the vital interests of the person concerned or of another natural person
- The processing may be explained by a necessity linked to the execution of a mission in the public interest or in the exercise of public authority
- The processing and collection of personal data is necessary for the purposes of legitimate and private interests pursued by the data controller or by a third party.

ARTICLE 3: PERSONAL DATA COLLECTED AND PROCESSED WHILE BROWSING THE SITE

A. DATA COLLECTED AND PROCESSED AND METHOD OF COLLECTION

The personal data collected on the StratMachina site are as follows: First name, Last name, Last name, Schools, Postal address, Email address, Bank details. This data is collected when the user performs one of the following operations on the site:
- When the user creates an account
- When the user buys a product. In addition, when paying on the site, proof of the transaction including the order form and the invoice will be kept in the site publisher's computer systems. The data controller will keep all the data collected in its site computer systems and under reasonable security conditions for a period of: 5 years.

Data collection and processing meet the following purposes:
- The user's personal data is collected in order to better understand their profile and personalize the commercial relationship with them.

B. TRANSMISSION OF DATA TO THIRD PARTIES

The data may be transmitted in particular to the third party (s) listed below: Google, Facebook, Stripe for the purposes of targeted commercial advertising

C. DATA HOSTING

The StratMachina site is hosted by: OVH SAS, whose head office is located at the following address: 2 rue Kellermann — BP 80157 — 59053 Roubaix Cedex 1 — France. The data collected and processed by the site are exclusively hosted and processed in France.

ARTICLE 4: DATA CONTROLLER AND DATA PROTECTION OFFICER

A. THE DATA CONTROLLER

The person responsible for processing personal data is: Oussama Atlassi. He can be contacted in the following way:
- By email: contact@stratmachina.com
The data controller is responsible for determining the purposes and the means used for the processing of personal data.

B. OBLIGATIONS OF THE DATA CONTROLLER

The data controller undertakes to protect the personal data collected, not to transmit them to third parties without the user having been informed and to respect the purposes for which this data was collected. The site has an SSL certificate to ensure that the information and the transfer of data passing through the site are secure. An SSL certificate (“Secure Socket Layer” Certificate) aims to secure the data exchanged between the user and the site. In addition, the data controller undertakes to notify the user in the event of correction or deletion of data, unless this involves disproportionate formalities, costs and procedures for the user. In the event that the integrity, confidentiality or security of the user's personal data is compromised, the data controller undertakes to inform the user by any means.

C. THE DATA PROTECTION OFFICER

In addition, the user is informed that the following person has been appointed Data Protection Officer: Oussama Atlassi.The role of the Data Protection Officer is to ensure the proper implementation of national and supranational provisions relating to the collection and processing of personal data. He is sometimes called DPO (for Data Protection Officer). The data protection officer can be reached as follows:
- By email: contact@stratmachina.com

ARTICLE 5: USER RIGHTS

In accordance with the regulations concerning the processing of personal data, the user has the rights listed below. In order for the data controller to grant his request, the user is required to provide him with: his first and last name as well as his e-mail address, and if relevant, his account number or personal space or subscriber number. The data controller is required to respond to the user within a maximum of 30 (thirty) days.

A. PRESENTATION OF THE USER'S RIGHTS IN TERMS OF DATA COLLECTION AND PROCESSING

a. Right of access, rectification and right to erasure

The user can read, update, modify or request the deletion of data concerning him, by respecting the procedure set out below: the user must send an email to the person responsible for processing personal data, specifying the subject of his request and using the contact email address provided above. If they have one, the user has the right to request the deletion of their personal space by following the following procedure: the user must send an email to the data controller, specifying the number of their personal space. The deletion request will be processed within 10 working days.

b. Right to data portability

The user has the right to request the portability of his personal data, held by the site, to another site, by complying with the following procedure: the user must make a request for the portability of his personal data to the data controller, by sending an email to the address provided above.

c. Right to limitation and opposition to data processing

The user has the right to request the limitation or to oppose the processing of their data by the site, without the site being able to refuse, unless the site can demonstrate the existence of legitimate and compelling reasons, which may prevail over the interests and rights and freedoms of the user, which may prevail over the interests and rights and freedoms of the user. In order to request the limitation of the processing of their data or to express an opposition to the processing of their data, the user must follow the following procedure: the user must make a request to limit the processing of their personal data to the data controller, by sending an email to the address provided above.

D. Right not to be the subject of a decision based exclusively on an automated process

In accordance with the provisions of Regulation 2016/679, the user has the right not to be the subject of a decision based exclusively on an automated process if the decision produces legal effects concerning him, or significantly affects him in a similar way.

e. Right to determine the fate of data after death

The user is reminded that he can organize what should be the fate of his data collected and processed if he dies, in accordance with law No. 2016-1321 of October 7, 2016.

f. Right to refer the matter to the competent supervisory authority

In the event that the data controller decides not to respond to the user's request, and the user wishes to contest this decision, or, if he believes that one of the rights listed above has been infringed, he is entitled to refer the matter to the CNIL (Commission Nationale de l'Informatique et des Libertés, https://www.cnil.fr) or any competent judge.

B. PERSONAL DATA OF MINORS

In accordance with the provisions of article 8 of European Regulation 2016/679 and the Data Protection Act, only minors aged 15 or over may consent to the processing of their personal data. If the user is a minor under the age of 15, the consent of a legal representative will be required so that personal data can be collected and processed. The publisher of the site reserves the right to verify by any means that the user is over 15 years old, or that he has obtained the agreement of a legal representative before browsing the site.

ARTICLE 6: CONDITIONS FOR MODIFYING THE PRIVACY POLICY

This privacy policy can be viewed at any time at the foot of the site. The publisher of the site reserves the right to modify it in order to guarantee its compliance with the law in force. Therefore, the user is invited to come and consult this privacy policy regularly in order to keep up to date with the latest changes that will be made to it.

ARTICLE 7: ACCEPTANCE BY THE USER OF THE PRIVACY POLICY

By browsing the site, the user certifies that he has read and understood this privacy policy and accepts its conditions, in particular with regard to the collection and processing of his personal data.