Personal Data Protection Policy

MÉRIEUX UNIVERSITÉ is aware and actively supporting protection of personal data for its suppliers and/or customers, and/or training interns, for all who access the MÉRIEUX UNIVERSITÉ Intranet site, and in general for all individual subject for whom personal data that could be treated.

The purpose of the Personal Data Protection Policy of MÉRIEUX UNIVERSITÉ (Policy) is to provide important information on the MÉRIEUX UNIVERSITÉ processing of personal data as well as how the individual subject can exercise their rights . The Policy will also aims to meet the requirements of the new regulation (Regulation #2016/679) General Data Protection Regulation (GDPR) for protection of personal data applicable since 25th May 2018.

1. WHO IS THE DATA CONTROLLER OF THE PERSONAL DATA PROCESSING ?

The data controller which is responsible of the purpose and the means of the processing of the personal data :

Mérieux Université – 113 Route de Paris – 69160 Tassin La Demi-Lune France

2. WHAT ARE THE CATEGORIES OF PERSONAL DATA COLLECTED AND PROCESSED?

The term of “personal data” means any information relating to an identified or identifiable natural person. MÉRIEUX UNIVERSITÉ does not collector process minor child’ personal data .

MÉRIEUX UNIVERSITÉ may, depending on the case, collect and process all or part of the following personal data: first and last names, date of birth, professional and/or personal postal address, fixed and/or mobile telephone number and/or personal number fax, professional and/or personal email address, RPPS number…

MÉRIEUX UNIVERSITÉ respects the principle of minimization and thus collects and processes only the necessary personal data for the purpose(s) for which the personal data are processed.

3. FOR WHAT REASONS/PURPOSES AND ON WHAT LEGAL BASIS ARE THE PERSONAL DATA COLLECTED AND PROCESSED?

MÉRIEUX UNIVERSITÉ collects and processes your personal data for different reasons/purposes legitimately determined to fulfill the following purposes:

Depending on the purpose, the processing of your personal data is based either on the execution of the contract (management and monitoring of the customer relationship and/or trainee), or on the legitimate interest of MÉRIEUX UNIVERSITÉ (respond to contact forms via the

websites, or the sending of information, newsletters, sending invitations to events) or for being compliant with a legal requirement (manage the requests of the persons concerned related to the exercise of their rights in relation to their personal data).

4. TO WHOM YOUR PERSONAL DATA CAN BE TRANSFERRED ? WHO CAN BE SENT PERSONAL DATA?

We do not share your personal data with any third parties other than those identified below.

MÉRIEUX UNIVERSITÉ may be required to transmit your personal data to different categories of recipients:

In any case, MÉRIEUX UNIVERSITÉ shall not to transfer personal data to third parties other than those listed above.

MÉRIEUX UNIVERSITÉ may, however, be required to communicate personal data to be in compliance with a legal obligation, at the request of an administrative or judicial authority that requests it or for the exercise of a legitimate interest such as the defense of its rights. Personal data is not transferred outside of the European Union.

5. HOW LONG ARE PERSONAL DATA KEPT?

Your personal data are kept for the time necessary to achieve the purposes for which they were collected and for the minimum retention period provided by law.

Your personal data are stored and used for different durations according to the purposes described above. Specifically:

At the end of this retention period, personal data will be destroyed.

Personal data may be archived beyond the retention period described above for the purpose of mandatory legal obligation, to exercise a legal claim.

6. SECURITY

MÉRIEUX UNIVERSITÉ implements all technical and organizational measures to ensure the security of the processing of your personal data and their confidentiality.

To ensure the security of your personal data, especially to prevent it from being distorted, damaged, or that unauthorized third parties have access to it, MÉRIEUX UNIVERSITÉ takes all the necessary precautions, in view of the nature of the data and the risks presented by the processing (including the physical protection of the premises, the implementation of authentication processes with personal and secure access via confidential username and passwords).

7. DATA COLLECTED IN CONNECTION WITH THE USE OF THE MÉRIEUX-UNIVERSITÉ WEBSITE.

In accordance with the laws on the protection of personal data, you are informed that by connecting to the website of MÉRIEUX UNIVERSITÉ, personal information about you will be automatically or voluntarily collected, stored and used under the conditions defined below. If your do not wish this personal information to be collected, stored and used you Mérieux Universitést contact MÉRIEUX UNIVERSITÉ at the following email address: communication@merieux-universite.com

The personal information collected during each connection to the site can come from:

The personal information collected will only be used by MÉRIEUX UNIVERSITÉ and Institut Mérieux Group companies and, unless otherwise specified at the time of collection, will not be disclosed or shared with third parties for any purpose whatsoever.

The personal information collected during each connection will be used to trace your course on the site to allow MÉRIEUX UNIVERSITÉ to establish statistics on the most visited pages and, more generally, to control and improve the operation of the site;

Personal information collected during your participation in discussion forums, surveys or online surveys, when you subscribe to our newsletter or other similar requests of registrations will only be used for the purpose for which this information was sent and collected. Any subscription to a newsletter may be canceled at any time by sending an e-mail to the following email address available on MÉRIEUX UNIVERSITÉ website: communication@merieux-universite.com

8. WHAT ARE YOUR RIGHTS REGARDING THE PROCESSING OF YOUR PERSONAL DATA?

In accordance with the regulations, you have the right to access your personal data, to rectify it, to object to its processing or to obtain its limitation, deletion or portability where applicable. In addition, you can withdraw your consent at any time for processing that are based on it, or ask to no longer receive our communications relating to information, announcements, wishes, newsletters and invitations to events organized by MÉRIEUX UNIVERSITÉ. You can file a complaint with the CNIL if you consider that your rights are not respected. For more details on your rights, we invite you to consult the sections below.

Depending on the processing, you have the following rights:

9. HOW TO EXERCISE YOUR RIGHTS CONCERNING YOUR PERSONAL DATA?

In general, to exercise your rights and for any questions or difficulties relating to the processing of your personal data and your rights, you can contact Mérieux Université:

10. CHANGES

Mérieux Université reserves the right to adapt the Policy and agrees to inform you on its website of changes or additions.

This version of the Policy was last updated on 11 June 2019.