PRIVACY POLICY ON WEBSITES

This privacy policy (hereinafter “Policy”) defines and informs users of WALLIX websites (hereinafter the “User(s)”) of the conditions of collection, use and protection by WALLIX of personal data (hereinafter the “Personal Data”), from  WALLIX websites wallix.com,  investors.wallix.com or ot.security.com (hereinafter the “Website(s)”), as well as their rights related to the use of such Personal Data.

This Policy may be modified or supplemented at any time by WALLIX, in particular in order to comply with any new law, new regulation, or technological evolution. In such a case, the date of its update will be clearly mentioned at the top of this Policy. These modifications bind any User of a Website as soon as they are upload on the Website. The User should therefore regularly consult this Policy in order to be aware of any changes.

I. PERSONAL DATA

WALLIX undertakes to ensure that the collection and processing of User’s Personal Data comply with the General Data Protection Regulation adopted by the European Parliament on 14 April 2016, and the Data Protection Act of 6 January 1978 as amended, WALLIX informs Users of the following terms:

1. Identity of the Data Controller

The Data Controller is WALLIX, having its registered office at 250 bis, rue du Faubourg Saint-Honoré, 75008 PARIS – France.

Tel. : + 33 (0)1 53 42 12 90 ; Fax : + 33 (0)1 43 87 68 38.

Email: privacy@wallix.com

2. Personal Data collected

WALLIX, as Data Controller, is required, as part of its activities, to collect, consult, use, modify, store, transmit and delete Personal Data provided via the contact form made available to Users on the Webites.

This Personal Data is mostly collected directly from the Users, the persons concerned, in the following cases, without this list being exhaustive:

·       Request for information on WALLIX Website;

·       Subscription to a free trial;

·       Browsing on WALLIX Website and/or consulting WALLIX products and services;

·       Request to be contacted by a WALLIX sales representative;

·       Upload a document to WALLIX Website;

·       Response to a job offer on WALLIX Website.

As part of the collection activities mentioned above, WALLIX collects the following Personal Data:

·       User’s identity and contact data: surname, first name, email address, telephone number, company and position;

·       technical information related to navigation, including IP address;

·       in the context of a response to a job offer: identity and technical data, Curriculum Vitae.

3. Purposes of processing

The Personal Data collected is necessary for the processing of the customer database (commercial approach and contractual relationship) and files as part of its activity of selling products and services, and training.

WALLIX may process a User’s Personal Data for the purposes of:

(a)  provide them with the information or services they have requested (in particular sending the Newsletter, requests for a live demo, downloading the free trial version, registering for a training session or submitting an online application for a job offer); or

(b)  collect information enabling WALLIX to improve the Websites and WALLIX products and services (in particular by means of cookies); or

(c)  be able to contact the User about various events relating to WALLIX, including in particular product updates and customer support.

4. Recipients

Only WALLIX is the recipient of User’s Personal Data, which is used by WALLIX employees for the sole purpose of the processing for which it is intended.

Personal Data may not be transmitted to a third party except in the following cases:

(a)  the User has given his prior consent for the sharing of his Personal Data with third parties,

(b)  the sharing of the User’s Personal Data a said third party is necessary for the provision of the products or services requested by the User,

(c)  a competent judicial or administrative authority requires WALLIX to communicate such Personal Data.

(d)  transfer to the subcontractors used by WALLIX. WALLIX ensures that regarding Personal Data, its subcontractors contractually undertake to implement a level of protection equivalent to WALLIX protection and, in any event, compliant with the regulation.

5. Transfer to a third country of the European Union

WALLIX makes its best effort to store Personal Data within the European Union and require its hosting providers to host Personal Data on the territory of the European Union. However, WALLIX cannot guarantee that Personal Data will not be transferred outside the European Union, in particular for maintenance and support operations or when the User gave its consent to the deposit of third-party cookies (e.g. Google and LinkedIn).

As such, WALLIX makes its best efforts to guarantee a sufficient level of protection of User’s Personal Data that complies with the regulations. WALLIX ensures implementation of measures to comply with strict conditions of confidentiality, use and protection of the data, in accordance with applicable regulations, especially legal basis requirement for any transfer of Personal Data to a third country. As such, WALLIX ensures that its service providers are subject to an obligation of confidentiality, and to a limitation of transfers (i) either to a country recognized by the European Commission as ensuring an adequate level of protection, (ii) or to a country not offering adequate protection but subject to Standard Contractual Clauses of the European Commission binding on the provider and guarantee a sufficient level of protection of privacy and the fundamental rights of individuals.

6. Retention period

The User’s Personal Data is retained by WALLIX only for a period necessary for processing and adapted to the purpose of collection.

In the context of a contractual relationship, Personal Data may be retained for up to 10 years after the end of the contract, in particular due to accounting and tax obligations incumbent on WALLIX.

Regarding prospects, Personal Data may be retained for up to 3 years after the last contact from the prospect.

Personal Data transmitted as part of an application may be retained for a period of 2 years from their submission or the last contact of the candidate.

As part of the control of WALLIX’s information system, a User’s Personal Data, in particular technical information such as IP addresses, connection logs, pages visited, are retained for 6 months from their collection.

6. Security measures

WALLIX makes every effort to ensure the security of the Personal Data collected, in accordance with the state of the art and the security policy of WALLIX’s information systems.

7. Rights of data subjects

The User has the following rights concerning his Personal Data, which he can exercise:

–          by email to privacy@wallix.com  or

–          by post to WALLIX – 250 bis rue du Faubourg Saint Honoré- 75008 Paris

Right of access and communication of Personal Data

The User has the right to access the Personal Data concerning him and request that this Personal Data and the information processing carried out on this Personal Data be communicated to him.

Right to rectification of data

The User may request the rectification, updating, blocking or deletion of data concerning him which may prove to be inaccurate, erroneous, incomplete or obsolete.

Right to portability

The user may request the transfer of personal data collected with his or her consent or as part of the performance of a contract to another data controller where technically possible. The right to portability must not infringe the rights of third parties.

Right to oppose

The exercise of this right is only possible in one of the following two situations:

1. Where the exercise of this right is based on legitimate grounds; or

2. When the exercise of this right aims to prevent the Personal Data collected from being used for commercial prospecting purposes.

6. Response times

WALLIX undertakes to respond, after verification of the User’s identity, to his request for access, rectification or opposition or any other additional request for information within a reasonable period of time which may not exceed one (1) month from receipt of his request.

7. Complaint to the competent authority

If the User considers that WALLIX does not comply with its obligations regarding its Personal Data, it may send a claim to the CNIL, the supervisory authority (www.cnil.fr).

II. COOKIE POLICY

When connecting to WALLIX’s Website for the first time, the User is warned by a banner at the bottom of his screen that information relating to his browsing may be recorded in files called “cookies”.

WALLIX’s cookie policy allows the User to better understand the provisions implemented regarding navigation on the Websites. It informs the User in particular about all the cookies present on a Website, their purpose and gives the User the procedure to follow to configure them.

I. General information on cookies on WALLIX Websites

WALLIX, as publisher of the Websites, may install a cookie on the hard drive of the User’s terminal (computer, tablet, mobile, etc.) to guarantee optimal navigation on the Website used.

“Cookies” are small text files of limited size that allow WALLIX to recognize the User’s computer, tablet or mobile phone in order to personalize the services offered.

The information collected through cookies does not in any way identify the User by name. They are used exclusively for WALLIX’s own needs in order to improve the interactivity and performance of the Websites and to send the User content adapted to their interests. None of this information is communicated to third parties except when WALLIX has obtained the User’s prior consent or when the disclosure of this information is required by law, by order of a court or any administrative or judicial authority empowered to know it.

For better information of the User about data that cookies identify, the list below mentions the different types of cookies that may be used on the Websites, their name, purpose and retention period.

II. Setting cookie preferences

1. Any User may accept or refuse the deposit of cookies at any time.

When connecting to a Website for the first time, a banner briefly presenting information relating to the deposit of cookies and similar technologies appears at the bottom of the User’s screen. This banner warns the User that by continuing to browse the Website (by loading a new page or clicking on various elements of the Website for example), the User accepts the deposit of cookies on his terminal. The User is also deemed to have given his consent to the deposit of cookies by clicking on the “X” icon to the right of the banner at the bottom of his screen.

Depending on the type of cookie in question, the collection of the User’s consent to the deposit and reading of cookies on his terminal may be imperative.

a. Cookies exempt from consent

In accordance with the recommendations of the CNIL, certain cookies are exempt from the prior collection of the User’s consent insofar as they are strictly necessary for the operation of the Website or have the exclusive purpose of allowing or facilitating communication by electronic means. These include session ID, authentication, load balancing session cookies as well as cookies for customizing User’s interface. These cookies are fully subject to this policy insofar as they are issued and managed by WALLIX.

b. Cookies requiring the prior User’s consent

This requirement concerns cookies issued by third parties and which are qualified as “persistent” insofar as they remain in the User’s terminal until they are deleted or their expiry date.

As such cookies are issued by third parties, their use and deposit are subject to their own privacy policies, the link to which is mentioned below. This cookie family includes audience measurement cookies (in particular Google Analytics), advertising cookies (which WALLIX does not use) and social network sharing cookies (in particular from Facebook, YouTube, Twitter and LinkedIn).

Audience measurement cookies compile statistics on the use and use of various elements of the website (such as the contents/pages visited by the User). This data contributes to improving the ergonomics of the Websites. The following audience measurement tools are used:

o Google Analytics , whose the deactivation module of the service can be downloaded here : https://tools.google.com/dlpage/gaoptout?hl=fr.

o HUBSPOT whose privacy policy is available here: https://legal.hubspot.com/privacy-policy

o UPLAND LEADLANDER whose privacy policy is available here: https://uplandsoftware.com/privacy/

Social network sharing cookies are issued and managed by the publisher of the social network concerned. Subject to the User’s consent, these cookies allow the User to easily share part of the content published on the WALLIX Website, especially via a sharing application “button” depending on the social network concerned. Four types of social network sharing cookies are present on the WALLIX Website:

o Facebook, whose cookie policy can be consulted here: https://fr-fr.facebook.com/policies/cookies/

o LinkedIn, whose cookie policy can be consulted here: https://www.linkedin.com/legal/cookie-policy?_l=fr_FR

o Twitter, whose options dedicated to controlling or restricting the use of cookies as well as the cookie policy can be consulted here: https://support.twitter.com/articles/20170518#

o YouTube, whose help to delete cookies from the Google Chrome browser can be accessed from  the following link: https://support.google.com/youtube/answer/32050?hl=fr but also the complete cookie policy via the following link: https://www.google.fr/intl/fr/policies/technologies/cookies/

Subject to the User’s consent, the cookies issued and managed by GARTNER allow the User to be redirected to the GARTNER website. The cookie policy is available here: https://www.gartner.com/en/about/policies/privacy/cookie-policy

2. The User has various tools for setting cookies

The User’s browser offers him the opportunity to accept, refuse or modify the standard settings for depositing cookies so that all cookies are systematically rejected or that only a part of the cookies is accepted or refused depending on their issuer.

ATTENTION: WALLIX draws the User’s attention to the fact that the refusal to deposit cookies on their terminal is nevertheless likely to alter their user experience as well as their access to certain services or features of the Website used. If necessary, WALLIX declines all responsibility for the consequences related to the deterioration of browsing conditions that occur due to the User’s choice to refuse, delete or block the cookies necessary for the operation of the Website. These consequences cannot constitute damage and the User will not be able to claim any compensation as a result.

The browser also allows the User to delete existing cookies on his terminal or to notify him when new cookies are likely to be deposited on his terminal. These settings do not affect navigation but lose all the benefit provided by the cookie.

The tools made available to Users so that they can configure the cookies deposited on their terminal are as follows:

a. The setting of the User’s Internet browser

Each Internet browser offers its own cookie management settings. To find out how to change his preferences in terms of cookies, the User can access the menu of his browser provided for this purpose. The following links provide the necessary help for the main browsers used:

Chrome : https://support.google.com/chrome/answer/95647?hl=fr

Firefox : https://support.mozilla.org/fr/kb/activer-desactiver-cookies

Internet Explorer : https://support.microsoft.com/fr-fr/help/17442/windows-internet-explorer-delete-manage-cookies#ie=ie-11

Opera : http://help.opera.com/Windows/10.20/fr/cookies.html

Safari : https://support.apple.com/kb/PH21411?viewlocale=fr_FR&locale=fr_FR

For more information on cookie control tools, the CNIL website  https://www.cnil.fr/professionnel can be consulted.

b. Disabling Google Analytics

WALLIX Websites also use the Google Analytics audience measurement service. However, if the User does not wish his anonymized information to be transmitted to Google Analytics in order to generate reports on the usage statistics of a Website, the User can download and install the browser add-on for the deactivation of Google Analytics here: https://tools.google.com/dlpage/gaoptout?hl=fr. This device is compatible with Chrome, Firefox, Internet Explorer 11, Opera and Safari and will prevent any Google Analytics JavaScript code inserted on a WebsIte that the User consults, from sharing information about him.

For any query or additional request for information relating to this cookie policy, the User may contact WALLIX via the contact form or by sending an email to the privacy@wallix.com address.

CONTACT THE DPO
(Data Protection Officer)