Contact
Contact
My account

Privacy policy

TECLIB S.A.S., with a capital of €445,930, whose registered office is located at 231 Rue Saint-Honoré - 75001 Paris, France, registered with the Paris Trade and Companies Register under number 513 893 503, places great importance on compliance with applicable regulations regarding the processing and protection of personal data. 

The purpose of this Personal Data Protection Policy is to provide information regarding the processing we carry out in the course of our business activities, which include the design and development of open-source software solutions, as well as consulting, support, and hosting services.

TECLIB is committed to establishing, maintaining, and ensuring a relationship of trust and respect with regard to the protection of personal data, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter: the GDPR), as well as all applicable French regulatory provisions in this area.

Who is considered a data controller or a data processor?

A “Data Controller” is any natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing.

A “Data Processor” is any natural or legal person, public authority, agency, or other body that processes personal data on behalf of the Data Controller.

Consequently, TECLIB is, in principle, the Data Processor. This status may only be waived by mutual written agreement of the parties. Thus, TECLIB merely carries out the purposes determined by the Data Controller.

TECLIB’s sub-processors are: 

  • The server hosting provider OVH. These servers are hosted in Europe (France). No customer information is shared with this sub-processor, which provides only the hardware and network infrastructure; installation and operation are carried out directly by us;
  • The online payment service Stripe, used to ensure regular payment of the subscription;
  •  Sendgrid, an email relay service, which is used to relay GLPI email notifications when “PHP” mode (the default) is used and you do not specify your own SMTP in the GLPI configuration.

What personal data do we process?

TECLIB processes only personal data provided and/or hosted by the Data Controller in connection with the open-source solutions offered and in accordance with the general terms and conditions of sale, service, or partnership agreements. Such processing, if it occurs, is necessary to fulfill the purpose specified by the Data Controller. Except in cases where the solution is hosted as part of Cloud offerings (subject to general and/or specific terms and conditions), TECLIB does not process personal data, unless explicitly and in writing requested by the Data Controller and accepted by TECLIB.

Thus, in the context of Cloud offerings and in order to ensure access to all of our services, particularly those related to GLPI Network Cloud, we may be required to collect and process the following information:

  • Your customer information, including your email address, customer account password, and, if applicable, company name, contact’s first and last name, address, ZIP code, country, and VAT number. This information and data are retained after you complete your registration to allow you to access our services, as well as for billing purposes if you have selected a paid plan;
  • The password is not stored. However, to validate your login to your Bind account, an encrypted hash of the password, generated by a non-reversible SHA256 encryption algorithm, is created;
  • When subscribing to a paid plan, a backup is performed daily and stored on independent storage disks hosted by OVH in Europe (France). Only the last thirty (30) days are retained. 

If you subscribe to the paid plan, the following information and data are processed: 

  • SEPA direct debit if you have chosen SEPA payment; 
  • he last four (4) digits of your credit card, if you have opted for credit card payment. Full payment details are processed and stored by “Stripe” only. The last four (4) digits allow us to identify and analyze payment issues.

You may request the deletion of your account and the information listed above at any time by contacting us at the following address: 

 

TECLIB does not collect any personal data of any kind, nor does it request the provision of personal data classified as “sensitive” according to the definition and categorization set forth in Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016.

If such processing were to be carried out in order to achieve the purposes dictated by the Data Controller, TECLIB would require the Data Controller to provide the legal basis for the requested processing in order to justify it, in accordance with Article 9 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016. 

Legal basis for the processing of personal data?

All processing of personal data is based on the legally valid grounds provided by the data controller. Consequently, in the absence of a lawful basis, in accordance with the provisions of Article 6 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, TECLIB will not process any personal data. 

Does Teclib share personal data ?

TECLIB does not share any personal data unless expressly requested and documented by the Data Controller. 

However, TECLIB may be required to share data in order to comply with its legal obligations or orders from government authorities, such as judicial or financial authorities, state agencies, or public bodies, upon a legitimate request from them—that is, one based on a court order or injunction.

In such a case, TECLIB, as a Data Processor, shall inform the Data Controller of its obligation to share the data, unless said authorities require TECLIB to do otherwise. 

Who has access to personal data?

Personal data, when disclosed for the purposes specified by the Data Controller and/or to fulfill the requirements of the contract in force between the parties, is processed exclusively by duly authorized personnel and processors who are bound by confidentiality obligations. 

In the event of a personal data breach, as a Processor, Teclib cooperates with the Data Controller to fulfill all of its legal obligations to the supervisory authorities. The terms of this cooperation are detailed in the agreement regarding the processing of personal data, the “DPA” or “GDPR Agreement.”

Does TECLIB transfer personal data outside the European Union?

No personal data is transferred outside the territory of the European Union, the European Economic Area (EEA), and/or a country that does not provide a level of protection equivalent to that within the European Union and the EEA. 

However, the Data Controller is free to carry out such a transfer. Any transfer contemplated in violation of applicable legal provisions will not be carried out by TECLIB.

How long are the processed personal data retained?

We do not retain any personal data once the purpose of the processing has been fulfilled as determined by the Data Controller. However, a retention period may be specified in the public or paid offering of the GLPI Network Cloud service, in accordance with the general terms and conditions, applicable specific terms, or special terms agreed upon with the customer.

What are your rights, and how can you exercise them with TECLIB?

In accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, and applicable French regulations in this area, individuals whose personal data is being processed have the rights to access, rectify, erase, object to, and transfer their data, as well as the right to restrict the processing of their data and not to be subject to a decision based on automated processing. 

You may exercise your rights by contacting the Data Protection Officer of the Data Controller. TECLIB may forward your request only if it is a direct processor for the Data Controller and your data is processed as part of a service provided by TECLIB on behalf of the Data Controller. This clause does not create an obligation for TECLIB to process your request.

Contact information for the Data Protection Officer:

How can I stay informed about changes to this Privacy Policy?

We make a point of updating our privacy policy regularly and in line with technological advancements.

The latest version is available on our website, and, if necessary, we will notify you of any significant changes through our usual communication channels.

chevron-right
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram