- How their personal data is collected and processed. Personal data is any data that can identify a user. This includes the first and last name, age, postal address, email address, location of the user or his IP address;
- What are the rights of the users concerning these data;
- Who is responsible for the processing of the personal data collected and processed ;
- To whom this data is transmitted;
- Possibly, the policy of the site regarding “cookies” files.
General principles of data collection and processing
In accordance with the provisions of Article 5 of the European Regulation 2016/679, the collection and processing of data of the users of the site respect the following principles:
- Lawfulness, fairness and transparency: data can only be collected and processed with the consent of the user who owns the data. Whenever personal data is collected, the user will be informed that his/her data is being collected and for what purpose it is being collected;
- Limited purposes: the collection and processing of data is carried out to meet one or more of the purposes set out in these terms and conditions of use;
- Minimization of data collection and processing: only the data necessary for the proper execution of the purposes pursued by the site are collected;
- Conservation of data reduced in time: the data are kept for a limited period of time, of which the user is informed. If the duration of conservation cannot be communicated to the user;
- Integrity and confidentiality of the data collected and processed: the data controller undertakes to guarantee the integrity and confidentiality of the data collected.
In order to be lawful, and in accordance with the requirements of Article 6 of the European Regulation 2016/679, the collection and processing of personal data may only take place if they comply with at least one of the conditions listed below:
- The user has expressly consented to the processing ;
- The processing is necessary for the proper performance of a contract;
- The processing is in accordance with a legal obligation;
- The processing is necessary for the protection of the vital interests of the data subject or of another natural person;
- Processing may be necessary for the performance of a task carried out in the public interest or in the exercise of official authority;
- The processing and collection of personal data is necessary for the purposes of the legitimate and private interests pursued by the controller or by a third party.
Personal data collected and processed in the context of navigation on the site
Data collected and processed and method of collection
The personal data collected on the Waltio.co website are the following: First name, Last name, E-mail address.
This data is collected when the user performs one of the following operations on the site: Creation of the Waltio account
In addition, when a payment is made on the site, a proof of the transaction including the order form and the invoice will be kept in the computer systems of the site editor.
The person in charge of the treatment will keep in its computer systems of the site and in reasonable conditions of safety the whole of the collected data for a duration of : 3 years.
The collection and processing of the data are for the following purposes: To retrieve the account data, the transaction history
Transmission of data to third parties
The personal data collected by the site are not transmitted to any third party, and are only processed by the site editor.
The Waltio.co website is hosted by : Amazon, whose headquarters are located at the following address:
Amazon.com, Inc. Customer Service PO Box 81226 Seattle, WA 98108-1226
The host can be contacted at the following telephone number: (888) 280-3321
The data collected and processed by the site are transferred to the following country: US. This transfer of personal data outside the European Union is justified by the following reasons:
The data is hosted in the United States because the company has a contract with an American host
Data controller and data protection officer
Person in charge of data processing
The person in charge of processing personal data can be contacted in the following way:
The data controller is responsible for determining the purposes and means of processing personal data.
Obligations of the data controller
The data controller undertakes to protect the personal data collected, not to pass them on to third parties without the user’s knowledge and to respect the purposes for which the data was collected.
The site has an SSL certificate to ensure that the information and data transfer through the site is secure.
An SSL certificate (“Secure Socket Layer” Certificate) is intended to secure the data exchanged between the user and the site.
In addition, the data controller undertakes to notify the user in the event of rectification or deletion of the data, unless this would entail disproportionate formalities, costs and steps for the user.
In the event that the integrity, confidentiality or security of the user’s personal data is compromised, the data controller undertakes to inform the user by any means.
Data Protection Officer
Furthermore, the user is informed that the following person has been appointed as Data Protection Officer: Benjamin Chevallereau.
The role of the Data Protection Officer is to ensure the proper implementation of national and supranational provisions concerning the collection and processing of personal data. He is sometimes called DPO (for Data Protection Officer).
The Data Protection Officer can be reached in the following ways:
By email : firstname.lastname@example.org
Rights of the user
In accordance with the regulations concerning the processing of personal data, the user has the following rights.
In order for the data controller to comply with the user’s request, the user is obliged to provide the data controller with the following information: first and last name, e-mail address and, if relevant, account number or personal or subscriber number.
The data controller is obliged to respond to the user within a maximum of 30 (thirty) days.
Presentation of the user’s rights regarding data collection and processing
Right of access, rectification and deletion
The user may access, update, modify or request the deletion of data concerning him/her, by following the procedure set out below:
The user must contact the support service at email@example.com and specify the object of his request.
If the User has a personal space, he/she has the right to request the deletion of his/her personal space by following the procedure below:
The user must send an e-mail to firstname.lastname@example.org specifying the subject of his request. This one will be treated within 10 working days
Right to data portability
The user has the right to request the portability of his personal data, held by the site, to another site, by complying with the procedure below:
The user must make a request for portability of his personal data by sending an email to the data controller at email@example.com
Right to limit and oppose the processing of data
The user has the right to request the limitation or to object to the processing of his/her data by the site, without the site being able to refuse, except for demonstrating the existence of legitimate and compelling reasons, which can prevail over the interests and rights and freedoms of the user.
In order to request the limitation of the processing of his/her data or to formulate an opposition to the processing of his/her data, the user must follow the following procedure:
The user must make a request to limit the processing of his/her personal data to the data controller by sending an email to the address provided.
Right not to be subject to a decision based exclusively on an automated process
In accordance with the provisions of Regulation 2016/679, the user has the right not to be subject to a decision based exclusively on an automated process if the decision produces legal effects concerning him, or significantly affects him in a similar way.
Right to determine the fate of data after death
The user is reminded that he/she can organize what should be the fate of his/her collected and processed data if he/she dies, in accordance with Law no. 2016-1321 of 7 October 2016.
Right to refer to the competent supervisory authority
In the event that the data controller decides not to respond to the user’s request, and the user wishes to contest this decision, or, if he/she believes that one of the rights listed above is infringed, he/she is entitled to refer the matter to the CNIL (Commission Nationale de l’Informatique et des Libertés, https://www.cnil.fr) or any competent judge.
Personal data of minors
In accordance with the provisions of Article 8 of the European Regulation 2016/679 and the Data Protection Act, only minors aged 15 years or older may consent to the processing of their personal data.
If the user is a minor under the age of 15, the consent of a legal representative will be required in order for personal data to be collected and processed.
The site editor reserves the right to verify by any means that the user is over 15 years of age, or that he/she has obtained the consent of a legal representative before browsing the site. Also, the Site and the Services are not available for minors as mentioned in the Terms and Conditions.
The site editor reserves the right to modify it in order to ensure its compliance with the law in force.