Personal Data Protection Policy
As of 19/02/2025
Personal data: means any information, in any form whatsoever, relating directly or indirectly to an identified or identifiable natural person.
SITEC is aware of the urgent need to ensure the integrity, confidentiality and protection of the personal data of individuals and their privacy. As such, it undertakes to take all technical and organizational measures to ensure respect for the rights of individuals with regard to the protection of personal data defined in the General Data Protection Regulation (GDPR), adopted by the European Parliament on April 14, 2016, and the french Data Protection Act of January 6, 1978 ("IT and Liberties law").
This policy informs you of how SITEC uses and protects personal data. It complements the clauses set out in the General Terms and Conditions of Use (GTC – Legal Notices) relating to the processing of personal data.
- SITEC is committed to collecting and processing the personal data of individuals in a fair, lawful, transparent, clear, simple and documented manner.
- SITEC undertakes to collect personal data for explicit and legitimate purposes, and exclusively for processing for which the natural person has previously given her consent in an explicit, free, specific, informed and unequivocal manner.
- SITEC is committed to respecting the principle of minimizing personal data, ensuring that the data collected is necessary and adequate for carrying out the processing.
- SITEC undertakes to ensure that the concerned natural persons have been informed of the processing (right to information, articles 13 and 14 of the GDPR) which will be carried out, as well as of the actual recipients of the data (internal, external) and that their consent has been explicitly obtained.
Information for minors:
Minors must be aware of this policy and the General Terms of Use (GTU – Legal Notices) of our site, accompanied by their parents or legal representatives. Personal data of minors under 15 years of age will not be collected without the express authorization of the person concerned, coupled with the authorization of their parents or their legal representatives.
This policy may be modified or supplemented at any time and without notice, in particular to comply with any legislative, regulatory, jurisprudential or technological developments. In such a case, the date of its update will be clearly identified at the top of this policy. These modifications are binding on the user as soon as they are posted online. The user is invited to consult this policy regularly.
1/ Use of the site https://www.sitec.corsica
Generally speaking, you can visit the site without providing any personal information about yourself. In any case, you are under no obligation to provide any personal data to the Site Owner.
However, if you refuse, you may not be able to benefit from certain information or services. As such, the Owner may in certain cases ask you to provide your first and last name, postal address, email address, telephone number, company and position and other information about you (hereinafter your “Personal Data”). By providing this information, you expressly agree that it may be processed by the Owner of the Site, for the purposes indicated below as well as for the purposes possibly recalled at the end of each form.
In accordance with the General Data Protection Regulation (GDPR), the owner of the site informs you of the following points :
Identity of the controller
The Société Informatique et Télématique Corse (hereinafter “SITEC” or “owner”), registered at the RCS of Ajaccio under SIREN number 339 552 648, having its head office at the old road of Sartène, Vazzio, 20090 Ajaccio, represented by Mr. Philippe GUISEPPI, in his capacity as General Manager, is responsible for processing the data that it collects in the context of the use of the site www.sitec.corsica, as well as SITEC services.
Purposes of treatment
SITEC may process your Personal Information:
(a)for the purpose of providing you with the information or services you have requested (in particular: sending a Newsletter, an offer of services) ; and/or
(B)for the purpose of collecting information enabling us to improve the Site, products and services (in particular through cookies) ; and/or
(C)for the purpose of being able to contact you about various events relating to the commercial relationship, including in particular the updating of products and/or services, and customer support.
Legal basis
The processing described above is carried out on the basis of the Owner's legitimate interest in communicating and promoting its services.
Recipients
SITEC is the sole recipient of the personal data collected as part of this processing. This data, whether in individual or aggregated form, is never shared with a third party. Neither SITEC nor any of its subcontractors market the personal data collected for processing purposes.
Retention period
Your Personal Informations are kept only for the time necessary to fulfill the purpose of the processing. In any case, these data shall not be kept for more than 36 months.
2/ Execution of contracts
Identity of the controller
Société Informatique et Télématique Corse (hereinafter "SITEC"), registered a the RCS of Ajaccio under SIREN number 339 552 648, having its head office at l'ancienne route de Sartène, Vazzio, 20090 Ajaccio, represented by Mr. Philippe GUISEPPI, in his capacity as Managing Director, is responsible for processing the data it collects for the purpose of executing its contracts. Conversely, the services offered by SITEC that lead to the conclusion of a contract and the implementation of processing activities on behalf of its Clients qualify SITEC as a data processor under the instructions of a data controller.
As part of its commercial relations and the pursuit of its corporate purpose, SITEC is required to process personal data of the employees of its partners/service providers/suppliers/customers as data controller.
Purposes of treatment
- Relationship management:
As part of the execution of the contract between SITEC and a partner/service provider/supplier/client, the data processed by SITEC will be used for the purposes of commercial communication, commercial monitoring, accounting monitoring, recovery, satisfaction surveys, supplier/service provider/partner audits, and incident management.
Data processed
○ Identification data: name, first name, professional postal address, professional email address, telephone number
○ Correspondence data exchanged between SITEC and the designated representative of the partner/service provider/supplier/client, whether by email, teleconference, or support ticket.
○ Access data: IP address, identification number (registration number, identifier), logs to the Incident Manager interface.
Legal basis
The processing is carried out on the basis of the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Recipients
The data processed will be intended for SITEC employees. Identification and contact data may be communicated to third parties, stakeholders, whose involvement is necessary for the execution of the contract. The data may be transmitted to the competent judicial and/or administrative authorities upon request.
Retention period
The data concerned is kept in an active database for the entire duration of the contract between the parties. After the end of the contract, it is kept for 36 months, based on the legitimate interest of the data controller.
3/ Recruitment
Identity of the controller
The Société Informatique et Télématique Corse (hereinafter “SITEC”), registered at the RCS of Ajaccio under the SIREN number 339 552 648, having its head office at the ancien route de Sartène, Vazzio, 20090 Ajaccio, represented by Mr. Philippe GUISEPPI, in his capacity as Managing Director, is responsible for processing the data it collects as part of the recruitment processes.
Purpose of processing
As part of its recruitment activities, SITEC processes the personal data of individuals who have submitted their applications to SITEC, either in response to a job or internship offer or in response to a speculative application.
In the event of a person's recruitment, the data collected by SITEC would be intended to lead to the implementation of processing relating to the administrative management of personnel, the organization of work, the management of remuneration, the monitoring of careers and the management of training.
Data processed
- Identification data:
○ Name
○ First name
○ Date of birth
○ Special phone number
○ Private email address
○ Postal address
○ Photography (possible)
- Training data:
○ Diplomas
○ Certification and professional aptitude certificates
○ Training
- Professional situation data:
○ Positions held
○ Requested remuneration level
- Correspondence data:
○ Any personal data contained in an email, letter, or letter of recommendation
Legal basis
The above processing is carried out within the framework of SITEC's legitimate interest or for the performance of a contract.
Recipients
Only SITEC employees involved in the recruitment process will receive the data collected as part of the processing linked to the recruitment process.
Retention period
At the end of the recruitment process or analysis of the spontaneous application, formalized by written response (email or letter) to the person concerned, SITEC retains the processing data for a period not exceeding 2 years from the last contact, on the basis of its legitimate interest and on condition that the candidate has been informed.
In the event of the formalization of an employment contract/agreement between the parties, the management of the concerned person's personal data will be subject to the SITEC HR Personal Data management policy as well as to the information mention relating to data protection within the framework of the recruitment process.
4/ Our commitments regarding the Protection and Security of Personal Data
SITEC is committed to implementing all technical and organizational measures to ensure the security, integrity, availability, and confidentiality of the personal data collected. This commitment is structured around an Information System Security Policy (PSSI), as well as through security procedures across all of our physical and logical infrastructures. These procedures are subject to regular audits and reviews, contributing to the continuous improvement of the owner's processes and infrastructures.
In particular, SITEC ensures to :
○ Minimize the personal data that it collects and processes, and to collect only the personal data strictly necessary to achieve the purposes of the processing that it performs ;
○ Encrypt the personal data it stores ;
○ Document its personal data processing in a processing register ;
○ Map the personal data processed within its information systems ;
○ Formalize and implement an incident notification and alert procedure in the event of a personal data breach ;
○ Evaluate and minimize the risks associated with the operation of its information systems, or those it hosts on behalf of clients ;
○ Inform, raise awareness among and train its employees on procedures and best practices related to the protection of personal data (including sensitive and health data), in compliance with the ISO 27001, HDS, and GDPR quality standards.
○ Deploy, control and continuously improve technical and organizational measures capable of protecting its physical and logical infrastructures, its information systems, and the data they contain.
SITEC strives to require the same level of quality in the security processes of the subcontractors/co-contractors it may engage (see point below).
Subcontracting
Although it does not entrust the processing of personal data to subcontractors (as defined in Articles 27 and 28 of the GDPR), SITEC ensures that the subcontractors, service providers and suppliers with whom it contracts comply with the regulations in force and apply the security policies and procedures to their intended use. To this end, SITEC carries out regular checks on compliance with these policies and procedures, and raises awareness among its subcontractors/service providers/suppliers of its information security requirements.
5/ Rights of individuals
You have the following rights regarding your Personal Information. You can exercise these rights by writing to us at the postal address mentioned on the Site or by completing the Site's contact form.
- Right of access and communication of data (article 15 GDPR)
You have the faculty to access the Personal Information that concerns you.
However, due to the security and confidentiality obligation in the processing of personal data incumbent on SITEC, you are informed that your request will be processed subject to you providing proof of your identity, in particular by producing a scan of your valid identity document (in the event of a request using our contact form) or a signed photocopy of your valid identity document (in the event of a written request).
SITEC hereby informs you that it reserves the right, where applicable, to object to requests that are manifestly abusive or excessive (in particular due to their number, repetitive or systematic nature).
To help you in your process, particularly if you wish to exercise your right of access by means of a written request sent to SITEC's postal address, you will find by clicking on the following link a template letter developed by the French Data Protection Authority ("CNIL").
→ CNIL – Exercise your right of access
- Right to rectification of data (Article 16 of the GDPR)
Under this right, the law allows you to request the rectification, updating, locking or deletion of data concerning you that may be inaccurate, erroneous, incomplete or obsolete.
You can also define general and specific guidelines regarding the fate of personal data after your death (the concept of "digital death", Article 85 of the French Data Protection Act, known as "LIL"). If necessary, the heirs of a deceased person can demand that the death of their loved one be taken into consideration and make the necessary updates.
To help you in your process, particularly if you wish to exercise, on your own behalf or on behalf of one of your deceased relatives, your right of rectification by means of a written request to SITEC's postal address, you will find by clicking on the following link a template letter developed by the CNIL:
→ CNIL – Rectify inaccurate, obsolete or outdated data
- Right to erasure of data (Article 17 of the GDPR, “right to be forgotten”)
You can request the deletion of personal data concerning you, in particular when:
- The personal data are no longer necessary in relation to the purposes for which they were collected and processed;
- Your consent on which the processing(s) is based has been withdrawn;
- The processing of personal data is unlawful, there is no compelling legitimate reason for the processing or when the processing was carried out for commercial prospecting purposes, including profiling;
- A legal obligation provided for by Union law or by the law of a Member State to which SITEC is subject as Data Controller requires the erasure of personal data.
To help you in your process, particularly if you wish to exercise your right to be forgotten by means of a written request addressed to SITEC's postal address, you will find by clicking on the following link a template letter developed by the CNIL:
→ CNIL – Deleting information about you from a website
- Right to restriction of processing (Article 18 of the GDPR)
You may request that your personal data not be processed temporarily (limitation of their use), in particular in the event of a dispute or litigation concerning their accuracy, in the event of unlawful processing or in the event of exercising your right to object during the verification of whether the legitimate grounds pursued by the Data Controller prevail over yours.
Where processing has been restricted, such personal data may, with the exception of storage, only be processed with your consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.
You are informed in advance of the lifting of the processing limitation.
- Right to data portability (Article 20 GDPR)
You have the option to request to receive Personal Data concerning you in a structured, commonly used and machine-readable format.
You can also request that your Personal Data be transmitted directly to a third party of your choice (from one Data Controller to another) as soon as this is technically possible.
- Right to object (Article 21 of the GDPR)
The exercise of this right is only possible in one of two situations:
- Where the exercise of this right is based on legitimate grounds relating to the particular situation of the data subject; or
- When the exercise of this right aims to prevent the data collected from being used for commercial prospecting purposes, including profiling.
To help you in your process, particularly if you wish to exercise your right of opposition by means of a written request sent to SITEC's postal address, you will find by clicking on the following link a template letter developed by the CNIL:
→ CNIL – Object to data processing
- Right to lodge a complaint with the CNIL (article 77 of the GDPR)
In accordance with Article 77 of the General Data Protection Regulation, “Without prejudice to any other administrative or judicial remedy, any data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement, if he or she considers that the processing of personal data relating to him or her infringes this Regulation.”
→ CNIL – File a complaint online
Identity of the controller
The Société Informatique et Télématique Corse (hereinafter “SITEC”), registered at the RCS of Ajaccio under the SIREN number 339 552 648, having its head office at the ancien route de Sartène, Vazzio, 20090 Ajaccio, represented by Mr. Philippe GUISEPPI, in his capacity as Managing Director, is responsible for processing the data it collects in the context of the use of the site www.sitec.corsica, as well as SITEC services.
As part of its commercial relations and the pursuit of its corporate purpose, SITEC is required to process personal data of the employees of its partners/service providers/suppliers/customers.
For any request relating to your IT rights and freedom, you can contact the SITEC Data Protection Officer directly:
- By email : dataprivacy@sitec.corsica;
- By mail: to the attention of the Data Protection Officer, at the address mentioned in point 1.
Response times
SITEC undertakes to respond to your legal requests within a reasonable timeframe which may not exceed 1 month from receipt of your request, except in cases of force majeure justified by the data controller, or requests considered particularly complex.
