1. Introduction
Ostara is a brand of nke Instrumentation. The latter is committed to respecting the confidentiality and security of the personal data of its customers, partners, distributors and employees. As part of our business model, we collect and process personal data through our network of distributors in France and abroad, as well as in connection with the manufacture and sale of our products. The following policy describes how we collect, use and protect this data in accordance with the General Data Protection Regulation (GDPR)2. Data controller
The person responsible for processing personal data is the Human Resources Manager of nke Instrumentation, whose head office is located at 6 rue Gutenberg – 56700 Hennebont. You can contact our Data Protection Officer (DPO) at the following address: rgpd[@]nke.fr (remove the square brackets).3. Types of data collected
In addition to the security measures generally applicable within the company, there are specific measures for certain data. We collect the following data in the course of our activities:Treatment name | Purpose | Data category | Legal basis | Retention period | Manager | Safety measures |
Sales department | Identification data, commercial management | Surname, first name, e-mail address, telephone number, postal address of distributors and their contacts. | Contract performance | Contract duration +10 years | Marine and Instrumentation Operations Manager | Limited access (user management) |
Accounting department | Transaction and commercial data | Sales history, order data, billing and payment information | Legal obligation | Contract duration +10 years; according to legal requirements | Financial manager (with accounting firm) | Limited access (user management) |
HR Department | Employee data | Name, address, compensation information, performance tracking data | Performance Employment contract | During employment and up to 5 years after leaving the company | HR Manager | Limited access (user management) |
Purchasing department | Data on partners and suppliers | Information on subcontractors involved in product manufacturing | Legal obligations | In accordance with legal requirements | Purchasing Manager | Limited access (user management) |
Sales department | Location data | In the context of relations with our distributors abroad, we may collect geographical location information. | Contract performance | Contract duration +10 years; according to legal requirements | Marine and Instrumentation Operations Manager | Limited access (user management) |
E-marketing | Newsletters | Business development activities, mailing lists | Consent (unsubscribable) | Duration the time of consent | Communication department | Limited access (user management) |
Website | Navigation data | Cookies, IP address | Accept cookies before using the site | According to CNIL recommendations: 13 months | Communication department | Limited access (user management) |
Website (contact form) | Identification data | Last name, first name, e-mail address, telephone number | Contract performance | Contract duration +10 years | Marine and Instrumentation Operations Manager | Limited access (user management) |
Details of data collected on Group sites
The information collected on all Ostara websites (www.ostara.fr and www.nke-ostara.com ) is protected by the French Data Protection Act (loi “Informatique et Libertés” n° 78-17 du 06 janvier 1978). You have the right to access, rectify, object to and delete this information by simple request to nke Instrumentation, Zone Industrielle de Kerandré, 6 Rue Gutenberg 56700 HENNEBONT – FRANCE, or by e-mail to rgpd[@]nke.fr (remove the square brackets). Personal data collected via the contact form is limited to what is strictly necessary (data minimization) and processed internally.4. Legal basis for processing
We process your personal data on the following legal grounds:- Consent: When you have given your explicit consent for certain actions (for example, signing up for a newsletter or a specific program).
- Contract performance: For the performance of contracts with our distributors, suppliers and employees (e.g. order processing and deliveries).
- Legal obligations: When we have legal obligations to retain certain data (e.g. accounting management, compliance with tax laws).
- Legitimate interest: We have a legitimate interest in processing certain data in order to manage relations with our distributors and business partners and to improve our services.
5. Purpose of processing
The data we collect is used for the following purposes:- Managing relations with our distributors (in France and abroad), including order management and invoicing.
- Manufacturing and monitoring the production of our products via our network of subcontractors.
- To send you marketing and commercial communications (if you have consented), such as information on new products or exclusive offers.
- Management of legal and tax compliance (including accounting, audits).
- Employee relations management (e.g. performance monitoring, compensation management)
6. Recipients of data
nke Instrumentation does not sell or rent its contact list to third parties. We share your personal data with the following parties in the course of our business:- Distributors and business partners: To ensure the management of sales, distribution and after-sales support. These parties are required to respect data confidentiality in accordance with the RGPD.
- Subcontractors: Our subcontractors, such as product manufacturers, logistics providers, payment service providers, etc., may be required to process personal data as part of their mission. They act solely on the instructions of nke Instrumentation and are contractually bound to comply with the RGPD.
- Competent authorities: We will transmit your personal data to public authorities, if required by law (for example, in the context of audits or tax inspections).
7. Data retention period
We keep your personal data for as long as is necessary to fulfill the purposes for which it was collected. The retention period may be extended in accordance with our legal obligations (e.g. tax obligations). As a general rule, data relating to commercial transactions is kept for 10 years and employee data for 5 years after the end of their contract.8. Your rights
In accordance with the RGPD, pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, and repealing Directive 95/46/EC, as well as the Loi Informatique et Liberté (Law 78-17 of 6 January 1978 as amended), you may avail yourself of the following rights concerning your personal data:- Right of access: You have the right to request access to the personal data we hold about you (Article 15 of the GDPR).
- Right of rectification: You can request that your data be corrected if it is inaccurate or incomplete (Article 16 of the GDPR).
- Right to erasure: You can request the deletion of your personal data in certain circumstances (for example, if it is no longer necessary for the purposes for which it was collected) – Article 17 of the RGPD.
- Right to limit processing: You can request the limitation of the processing of your data in certain situations (Article 18 of the RGPD).
- Right to object: You may object to certain data processing, including commercial prospecting (Article 21 of the RGPD).
- Right to data portability: You can request the portability of your personal data in a structured format (Article 20 of the RGPD).
9. Data security
nke Instrumentation implements technical and organizational security measures to protect your personal data against loss, disclosure, alteration or unauthorized access. This includes the use of encryption systems, firewalls and strict access controls. nke Instrumentation manages access to data via security groups, both internally and on our services offered to our customers. The accounts used to access our data are created with a strong password policy. An IT charter has been drawn up for in-house use of IT. Our firewall and antivirus software analyze our Internet and internal flows, partitioning our networks. The latest updates are installed on all our computers. We deploy certificates on our websites. nke Instrumentation implements backups of our infrastructures. External IT interventions must pass through a bastion of administration.10. Subcontractors and international transfers
In the course of our business, some of our partners and subcontractors may be located outside the European Union. In such cases, we put in place appropriate measures to ensure that your personal data benefits from an adequate level of protection (for example, by means of standard contractual clauses).11. Specific cookie policy
This cookie policy explains what cookies are, what information we collect using cookies, and how you can control your cookie preferences.What are cookies?
Cookies are small text files stored on your device which are used to memorize basic information about your Internet browsing. Each cookie is sent by the server and stored on your computer for the duration of your session, or beyond, in order to recognize you next time you visit. To find out more about cookies, please see https://www.cnil.fr/fr/definition/cookie.What types of cookies do we use and why?
This site uses internal cookies that are essential to the operation of the web server, or are intended to optimize your browsing experience, and uses third-party services that also deposit cookies. The list below identifies the cookies used on this site, by category:Cookie
cookieyes-consent
duration: 1 year
description
CookieYes sets this cookie to remember users’ consent preferences so that their preferences are respected on subsequent visits to this site. It does not collect or store any personal information about visitors to the site.