Personal data protection policy Experts Program

Including the Cookies Policy

October 2023

 

You should pay particular attention to how your personal data is obtained, used and shared.

Also, this Personal Data Protection Policy (hereinafter the “Policy”) has been written to enable you to become aware of the practices and conditions under whichPrestaShop S.A – Limited Company registered in the Paris Trade and Companies Register under number 497 916 635 and whose offices are located at 198 Av. de France, 75013 Paris, collects and processes your Data as part of your application and/or registration for the Experts Program.

Given the constant evolution of laws and regulations regarding technology and tableData protection, the Policy may be regularly updated. If you are a Candidate or Member of the Experts Program (hereinafter the “Concerned person”) made accessible by PrestaShop Account, we invite you to regularly consult this page. In addition, you will be informed of substantial modifications by email. Substantial modifications are considered to be modifications relating to the main characteristics of the processing of personal data (addition of new purposes, etc.).

If one of the clauses of the Policy should be declared void or contrary to the regulations, it will be deemed unwritten but will not result in the nullity of the other clauses of the Policy.

The purpose of the Policy is to inform Data Subjects about the Data processing that we implement, about how we use this Data, share it and protect it, and about the rights you have over the Data concerning you.

We thank you for reading the Policy carefully in order to clearly understand our practices regarding the processing of your Data and inform you that the consultation and use of our Services are subject to this Policy.

If you do not agree with this Policy, we invite you not to submit your application to the Experts Program.

It is your responsibility to ensure that the Data communicated to PrestaShop is complete and up to date.

1. DEFINITIONS

The person concerned is informed that the following terms or expressions will have, whenever they begin with a capital letter in the body of the Policy (including its appearances and its preamble), whether they are used in the singular or plural, in the masculine or in the feminine, the meaning attributed to them below:

“CGU” designates the General Conditions of the Experts Program.
“Data” or “Personal Data” means any information relating to an identified or identifiable natural person within the meaning of Article 4.1 GDPR.
“PrestaShop (and/or) the Company” means the company PrestaShop S.A – Société Anonyme registered in the Paris Trade and Companies Register under number 497 916 635 and whose offices are located at 198 Av. de France, 75013 Paris
“Data controller” means the natural or legal person, public authority, service or other body which, alone or jointly with others, determines the purposes and means of the processing as defined in Article 4.7 of the GDPR .
“GDPR” means the General Data Protection Regulation 2016/679 dated April 27, 2016.
“Processor” means the natural or legal person, public authority, service or other body which processes personal data on behalf of the Data Controller as defined in Article 4.8 of the GDPR.
“Concerned Person” means the Candidate or, if their application is validated, the Member of the Expert Program whose Data is processed.

Terms starting with a capital letter and which are not defined above have the meaning given to them in the T&Cs.

2. PURPOSES & LEGAL BASES

PrestaShop may collect your Data for the following purposes:

Purposes Legal bases Details 
Managing your application for the Experts Program Contractual
commitment
CGU
Managing your registration for the Experts Program (provision of the Experts Portal, support, etc.) Contractual
commitment
CGU
Management of subscriptions to the Certification and visibility plan Contractual
commitment
CGU
Communicate with you (management of requests for
information and comments, responding to your contact
requests, advising you, communicating modifications and updates, alerting you in the event of security incidents, etc.)
Legitimate interest We consider that we have a legitimate interest in responding to questions or consultations that you have raised via the various contact channels
Marketing (Commercial prospecting, newsletters, etc.) Legitimate interest In accordance with the CNIL’s recommendations regarding B2B commercial prospecting, you are likely to receive commercial communications
Meet our legal requirements Legal obligation Respond to requests from authorities, comply with laws  and regulations, Respond to requests to exercise rights mentioned in article 7 of this Policy
Ensuring the security of our services (Fraud detection and prevention, information system security, etc.) Legitimate interest We consider that we have a legitimate interest in ensuring the security of our services
Litigation management Contractual
commitment
CGU
Invoice management (In case of subscription to a subscription as presented in the Experts Portal, royalties, etc.) Contractual
commitment
CGU

3. WHO PROCESS YOUR DATA?

3.1. Processing of your Data by PrestaShop employees

Your Data may be processed by PrestaShop employees.

Your Data may be transmitted to any buyer or other successor in the event of a merger, assignment, restructuring, reorganization, dissolution or other sale or transfer of part or all of the assets of PrestaShop due to uncertainties or bankruptcy, liquidation or other processes in which the Data of the Data Subjects of the various PrestaShop sites are among the assets transferred.

3.2. Processing of your Data relating to the PrestaShop Academy Platform

To find out more about the Processing of your Data as part of your access to the PrestaShop Academy Platform, we invite you to consult our dedicated personal data protection policy.

3.3. Processing of your Data by Processors

For the purposes of our activity, and for external processing needs, your Data may be communicated to service providers.

The list of Processors is available in Appendix 2.

The latter are obliged, by a Data processing agreement, to respect the confidentiality of the Data and to use it only for the purposes for which we transmit it to them. In addition, transfers of Data outside the European Union are subject to the signing of Standard Contractual Clauses with them.

4. LEGAL DISCLOSURE

We may also disclose your Data:

  • to comply with any legal mandate, law or legal process, including governmental and regulatory requests;
  • if we believe that disclosure is necessary or appropriate to protect the rights, property or safety of PrestaShop, its customers or other stakeholders. Such disclosure includes exchanging information with other companies and organizations for the purposes of protection against fraud and counterfeiting.

5. CONSERVATION

PrestaShop only keeps your Data for the necessary period. This retention period is not the same depending on the Data in question, the nature and purpose of the collection being likely to cause this duration to vary. Likewise, certain legal obligations impose a specific retention period.

When you contact PrestaShop using the various contact forms or telephone numbers, your Data will be kept for three (3) years from the last exchange with PrestaShop and then will be deleted.

Data relating to telephone recordings for service improvement and training purposes is retained for one (1) year from the recording.

When you exercise your rights mentioned in article 7 of this Policy, your Data will be kept for a period of five (5) years then deleted.

Candidate Data is kept for a period of three (3) years from submission of the application and then deleted.

Member Data will be retained throughout their participation in the Expert Program. In the event of suspension or termination, Member Data will be retained for a period of three (3) following the end of their participation in the Experts Program.

Finally, with regard to Data collected using cookies or trackers, they will be kept for a maximum period of twenty-five months as recommended by the CNIL. The lifespan of trackers is specified in the Cookies Policy available in Appendix 1.

Finally, we keep some of your Data for longer if necessary, for legitimate business purposes or if the law requires us to do so (whether for security purposes, financial data archiving, or fraud prevention and abuses).

When you delete or request the deletion of your Data, we ensure the effectiveness of this deletion or their conservation in anonymized form.

6. PROTECTION

Your Data is stored on secure servers and protected by firewalls and antiviruses.

We have implemented technical and organizational measures intended to guarantee the security and confidentiality of your Data against any accidental loss and against any unauthorized access, use, modification and disclosure.

Given the particularities inherent to the Internet, it is however impossible for us to guarantee optimal security of the exchange of information on this network.

We strive to protect your Data, but we cannot guarantee the absolute security of the information transmitted. You agree that you transmit your Data at your own risk.

We cannot be held responsible for non-compliance with privacy settings or security measures in place.

As such, you agree that the security of your information is also your responsibility. For example, it is your responsibility to keep secret the password allowing you to access your account.

7. RIGHTS

In accordance with the provisions of the applicable Data protection regulations, in particular European Regulation 2016/679 on Data protection, you have a right of access and a right of rectification to your Data.

You also have the right to define guidelines relating to the fate of your Data in the event of death.

In addition, subject to the conditions provided for by the GDPR for the exercise of these rights, you benefit from:

  • A right to erasure of your Data;
  • A right to limit the processing of your Data;
  • A right to object to the processing of your Data for legitimate reasons, in accordance with the article 21 of the GDPR ;
  • A right to portability of the Data you have provided;

When the processing of your Data is carried out on the basis of your consent, you can withdraw it at any time. You acknowledge, however, that processing carried out before the revocation of your consent remains perfectly valid.

However, in accordance with article 12.6 of the GDPR, for the exercise of these rights, PrestaShop, as Data Controller, reserves the right to ask you to prove your identity. We inform you that the Data used to prove your identity will be deleted once we have responded to your request.

You can exercise these rights by sending an email in French, English or Spanish to [email protected] or to the following address:

PrestaShop S.A Legal Department
198 Av. de France, 75013 Paris

We have one month to respond to any request relating to the exercise of your rights. This deadline may be extended by two months due to complexity or too many requests.

Finally, you have the right to lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL), in particular on its website.www.cnil.fr.

8. TRANSFERS

In accordance with article 3 above, Data may be transmitted to our Partners and/or Processors located outside the European Union. In this case, PrestaShop makes every effort to ensure the security of Data passing outside the European Union.

 

 

ANNEX 1.
COOKIE POLICY

When you visit or use the sites, PrestaShop or its Partner service providers may use cookies or any other tracking/tracking/automatic Data collection technology to store information to provide you with an improved, faster and more secure experience.

This cookie policy aims to help you better understand these technologies and our use of them.

1. WHAT IS A COOKIE ?

Cookies are small text files (most often consisting of letters and numbers), stored in the memory of your browser or device when you visit a website or view a message.

They allow a website to recognize the browser or device. Like most websites, PrestaShop uses technologies, mostly through small Data files stord on your device that allow us to record certain information when you visit or use our Site.

There are several types of cookies:

Session cookies: they expire as soon as the browser is closed and allow us to link your actions during this particular session,
Persistent cookies: they are stored on your device between browsing sessions and allow us to remember your preferences or actions on several sites,
Proprietary cookies: they are issued by the site you are visiting,
Third-party cookies: they are issued by a third-party site, separate from the site you are visiting.

2. WHAT TYPES OF COOKIES DOES PRESTASHOP USE?

  • Technical and necessary cookies

PrestaShop issues session cookies, strictly necessary for the proper functioning of the sites and your navigation on them. These cookies do not require prior consent to be placed on the terminal.

For more information on the use of the data collected, we invite you to consult the following page:

 

Cookie placed by Cookie name Purpose of the cookie Lifetime
Axeptio axeptio_cookies Management of user consents on our sites. 1 an
axeptio_all_vendors Management of user consents on our sites. 1 an
axeptio_authorized_vendo rs Management of user consents on our sites. 1 an
PrestaShop Language Contains the current language of the site. 1 an
Drupal.session_cache.prestashop_prev_url Used to limit access to the confirmation page which is displayed after downloading the PrestaShop solution in the Download page. 7 days
Drupal.session_cache.smart_ip Stores user location details based on their IP address. This data is only used to determine which regional variant of the site to display to users. The data is not stored permanently. 7 days
Session_id Records user session IDs. Identifies the user’s http session and a user’s requests during a session. Optional
has_js Determines whether JavaScript is enabled so that Drupal performs user experience-enhancing operations. Browsing
session
Cloudlfare __cf_bm This cookie is necessary for bot protection. 30 min
Forum ips4_IPSSessionFront This cookie contains the ID of your current session. Browsing
session
ips4_forum_view This cookie is set for information about the appearance of the forum. 1 an
ips4_ipsTime zone This cookie is set by JavaScript to detect the user’s local time zone so that the time can be automatically updated. Browsing
session
ips4_hasJS This cookie is set by JavaScript and is read later to determine whether JavaScript is supported by the user agent. 1 day

 

  • Analytical cookies

PrestaShop may use cookies or trackers allowing it to evaluate the performance of the Site, its applications, services and tools, particularly in the context of analytical practices, to help it understand how visitors use the Site, to detect if you have consulted a product or a link or to improve the content of its Site, its applications, its services or tools.

For more information on the use of the data collected, we invite you to consult the following page:

 

Cookie placed by Cookie name Purpose of the cookie Lifetime
Google Analytics _ga Allows us to broadcast our advertising messages on the Google network. 13 months
_gat_UA- nnn Assigns an identifier to each visitor to distinguish them. Browsing session
_gid Allows us to broadcast our advertising messages on the Google network. 24 hours
Content square _cs_id This cookie contains an anonymous ContentSquare user ID. 13 months
_cs_s This cookie contains the number of pages viewed in the current session for the ContentSquare tool. 30 minutes
_cs_mk This cookie is used for integration with Google Analytics. 30 minutes
_cs_vars This cookie is used by ContentSquare to create analysis variables. Browsing session
_cs_c This cookie is used by ContentSquare to save the user’s consent to data collection. 13 months
_cs_same_site This cookie allows the user to be identified via a unique identifier. Browsing session

 

  • Cookies or trackers allowing targeted ads to be offered

Partner service providers help us with various aspects of our business, such as the operation of the Site, our services (for example, the chat tool), our advertising and our tools. These cookies require prior consent to be placed on the terminal.

These partner service providers may also collect information that allows them to identify your device through our services (third-party cookies) and/or collect information that allows them to identify your device, such as your IP address or other unique identifier .

 

Cookie placed by Cookie name Purpose of the cookie Cookie duration
DoubleClik Google test_cookie Allows us to broadcast our advertising messages on the Google network. Browsing session
 _gcl_au Allows us to broadcast our  advertising messages on the Google network. 3 months
AntVoice off-mid unique AntVoice browser identifier 13 months
of-sess-i d-380 identifier of a browsing session on a specific site 30 min
off-tp-ad x Technical cookie indicating the identity synchronization status with the Google partner 2 days
of-tp-bs w Technical cookie indicating the identity synchronization status with the Bidswitch partner 2 days
of-tp-id- set technical cookie to validate that the browser accepts third party cookies 2 days
Artefact floodligh ts DV360 This tag allows us to improve our conversion tracking. 1 an
Impact IR_PI Partnership management 720 days
IR_1761 2 Partnership management Browsing session
IR_gbd Partnership management Browsing session
Segment analytic s.js This tracker allows the tracking of interactions between the user and the page. 1 an

 

  • Cookies allowing you to personalize your browsing

To offer you a better user experience, PrestaShop uses the services of AB Tasty, Content Square and Hubspot. These cookies require prior consent to be placed on the terminal. To obtain more information on the use of the data collected by them, we invite you to consult the following pages:

 

Cookie placed by Cookie name Purpose of the cookie Lifetime
AB Tasty ABTasty Information for A/B tests. 13 months
ABTasty Session AB Testing user session. Browsing session
ABTasty Domain Test Information for A/B tests. A few minutes
Hubspot hub spot Allows visitor authentication. 13 months
    hstc Use for timestamp. 12 months
    hssc This cookie tracks sessions. It is used to determine whether HubSpot should increase the session number and timestamp data in the hstc cookie. 30 min
    hssrc This cookie is set to determine whether the visitor has reset their browser. In the absence of this cookie when HubSpot processes cookies, the session is considered new. End of session
Drift drift_ca mpaign_ refresh This is the session ID token. It is used to link your website visitor to a current website session in the Drift system. 30 minutes
drift_aid This is the anonymous identification token. It is used to link your website visitor to the profile in the Drift system. 24 months
Hotjar _hjSessionUser This cookie keeps the Hotjar user ID, unique for this site, on the browser. This ensures that behavior on subsequent visits to the same site will be attributed to the same user ID. 30 min
_hjSession This cookie contains data from the current session. This means that subsequent requests in the session window will be assigned to the same Hotjar session. 12 months
Zendesk      zlcmi d This cookie is used to provide a live customer chat service on our Site. This cookie allows you to continue chatting with us as you browse the different pages of our Site, or when you return to the Site. 12 months

 

  • Social media cookies

PrestaShop services may include third-party applications to provide you with the ability to share content on social networks. These cookies require prior consent to be placed on the terminal

To obtain more information regarding cookies issued by social networks, we invite you to consult the following pages:

 

Cookie placed by Cookie name Purpose of the cookie Lifetime
Facebook _fbp Encrypted Facebook ID and Browser ID. 3 months
Linkedin bscookie Allows you to track usage of integrated services. 12 hours
just Allows you to store custom variables such as language.Browsing session Browsing session
lissc Allows you to track usage of integrated services. 12 months
lidc Allows you to track usage of integrated services. 24 hours
UserMatchHistory Allows Linkedin to offer you targeted advertisements. 2 months
Twitter personalization_id Identifies visitors from Twitter. 13 months
Quora m-b Identifies visitors from Quora 12 months

3. HOW TO MANAGE THE DEPOSIT AND READING OF COOKIES?

Certain features of our sites, services, applications and tools are made available to you only through these cookies or trackers.

However, refusing to use these technologies may result in the unavailability of certain features of our services.

For more information on blocking, removing or disabling these technologies, see your browser or device settings.

For third-party cookies, you can configure your browser settings to refuse all third-party cookies.

 

 

ANNEX 2.
PROCESSORS

The following Processors may process your Data:

Processors Services provided Country of head office
GOOGLE CLOUD PLATFORM Hosting of data relating to the provision of our services UNITED STATES
IMPARTNER Editor of the Experts Portal UNITED STATES
CHARGEBEE INC. Billing tool for recurring subscriptions UNITED STATES
STRIPE, INC. Managing recurring payments Ireland
ATLASSIAN
for Jira
Ticket management software UNITED STATES
ZENDESK INC. Support UNITED STATES
ACTIVE CONTACT Support Tunisia
SIFAST Support Tunisia
VOCALCOM
for Hermes360
Business telephony solution France
AIRCALL SAS Business telephony solution France
SENDSAFELY INC. Support UNITED STATES
GURU TECHNOLOGIES, INC. Support UNITED STATES
ZOHO CORPORATION PVT. LTD. Support UNITED STATES
HUBSPOT, INC. Our customer relationship management tool. UNITED STATES
FUNCTIONAL SOFTWARE, INC.
via sentry.io
Bug finding software UNITED STATES
MIXPANEL INC. Business Analytics Platform UNITED STATES
SEGMENT.IO, INC. Business Analytics Platform  UNITED STATES
HOTJAR LTD. Business Analytics Platform UNITED STATES
GOOGLE CLOUD
for Looker
Business Analytics Platform UNITED STATES
GOOGLE IRELAND LIMITED
for Google analytics for DoubleClick           
Business Analytics Platform UNITED STATES
CONTENTSQUARE Tracking France
AB TASTY Tracking France
CLOUDFLARE Tracking UNITED STATES
TAPFILIATE Tracking UNITED STATES
DRIFT.COM, INC. Tracking UNITED STATES
ANTVOICE Tracking France
ARTEFACT Tracking France
FACEBOOK Tracking UNITED STATES
LINKEDIN Tracking UNITED STATES
TWITTER Tracking UNITED STATES
QUORA Tracking UNITED STATES