Personal data

Privacy policy

This policy explains what data is processed when you contact HOSPIRIS, use its client portal or take part in an assignment, why it is processed and how you may exercise your rights.

Data controller

David Schmidt — HOSPIRIS
26 rue Bosquet, 75007 Paris, France
contact@hospiris.com

Data concerned

Depending on your relationship with HOSPIRIS, the following categories of data may be processed:

  • contact details: name, email address, telephone number, property or organisation, job title, subject and content of correspondence;
  • client account data: username, password stored only as a secure hash and account status;
  • technical and security data: login date and time, session information and a pseudonymised fingerprint of the IP address used to limit abusive attempts;
  • audience data: page viewed, date and time, device type, browser, language and referring domain; the audience measurement tool never records the raw IP address;
  • assignment data: property information, contacts, observations, audit-grid responses, photographs, comments, recommendations and deliverables;
  • personal data that may appear in supplied documents, field observations or publicly available reviews analysed for an assignment.

Fields marked as required are necessary to answer a request, create access or perform the assignment. Without them, HOSPIRIS may be unable to provide the relevant service. Other information is optional.

Purposes and legal bases

  • answer requests for information or contact;
  • prepare a quotation or assignment proposal at your request;
  • prepare, perform and follow up an assignment and produce the agreed deliverables;
  • create, administer and secure client accounts and make results available;
  • manage the administrative, contractual and accounting aspects of the professional relationship;
  • protect website security and prevent automated abuse.
  • measure website traffic in aggregate form in order to improve content and usability.

Depending on its purpose, processing is based on pre-contractual steps or performance of the contract, compliance with HOSPIRIS’s legal obligations, or its legitimate interests in answering enquiries, conducting and documenting assignments, protecting its systems and defending its rights.

Recipients

Data is accessible only to people authorised by HOSPIRIS and, where necessary, consultants working on the assignment within the limits of their role and subject to confidentiality obligations. It may also be processed by providers required for hosting, backups and email. Deliverables are accessible to the relevant client and people authorised by that client. Data is neither sold nor rented.

Retention

  • enquiries that do not lead to a commercial relationship: no more than three years after the last exchange;
  • client accounts: for as long as access remains open, then deleted or anonymised no later than twelve months after closure;
  • security logs and related data: no more than twelve months, except where records are required to handle an incident;
  • pseudonymised audience data: no more than twelve months;
  • assignment data and deliverables: throughout the contractual relationship and for five years after completion, unless another period is agreed or a longer legal requirement applies;
  • accounting records and supporting documents: ten years where required by law.

Security

HOSPIRIS uses HTTPS encryption, passwords stored as non-reversible secure hashes, protected sessions, login-attempt limits, restricted access rights, backups and separation between client areas. No internet-connected system can offer absolute security; please do not send sensitive or confidential information through the public form without prior agreement.

Your rights

You may request access, rectification or erasure, restriction of processing, object to certain processing and, where applicable, request data portability.

To exercise your rights, email contact@hospiris.com. Proof of identity will be requested only where necessary to prevent disclosure to an unauthorised person.

You may also lodge a complaint with the French data protection authority, the CNIL.

Policy updates

This policy may change to reflect developments in the website, services or applicable law. The version published here is the current version.