Data protection
Privacy policy
Last updated
This page is a courtesy translation. In case of doubt or divergent interpretation, only the French version is authoritative and prevails over all other languages.
AIC AIRPORTS attaches fundamental importance to the privacy of its contacts, prospects, clients, suppliers and of the users of aicairports.com. The purpose of this policy is to set out transparently how personal data is processed.
It is written in accordance with regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the “GDPR”) and with French act no. 78-17 of 6 January 1978 as amended, known as the “Informatique et Libertés” act.
Identity and contact details of the data controller
The controller of the personal data collected through the site and in the course of the commercial relationship is:
- Data controller
- AIC AIRPORTS — SARL
- Registered office
- 1, rue de l'abbé Grégoire, 91000 Évry-Courcouronnes, France
- SIREN
- 106 413 917
- Represented by
- Maëvane MASSAMBA-BIFOUTY
- GDPR contact
- contact@aicairports.com
AIC AIRPORTS has not appointed a data protection officer (DPO): such an appointment is not mandatory given the company's activity (article 37 of the GDPR). Any request relating to personal data may be addressed directly to the controller by email at contact@aicairports.com.
Data collected and processing carried out
AIC AIRPORTS undertakes to collect only the data strictly necessary for the purposes pursued, in application of the principle of data minimisation (article 5-1-c of the GDPR).
Register of processing activities
| Purpose | Categories of data | Legal basis | Retention period |
|---|---|---|---|
| Responding to contact or quotation requests (site form, email) | Surname, first name, job title, company name, email address, telephone, message | Pre-contractual measures at the request of the data subject (art. 6-1-b of the GDPR) | 3 years from the last contact if the relationship does not materialise |
| Client relationship management (quotations, orders, invoicing, assignment follow-up) | Identification data, job title, business contact details, contractual and financial data | Performance of the contract (art. 6-1-b of the GDPR); accounting legal obligation (art. 6-1-c) | Duration of the contractual relationship + 10 years (accounting and tax obligations, art. L. 123-22 of the French commercial code) |
| B2B commercial prospecting | Surname, first name, job title, business email address, telephone, company name | Legitimate interest of the controller (art. 6-1-f of the GDPR) — CNIL recommendation on B2B prospecting | 3 years from the last contact initiated by the prospect |
| Supplier and partner management (subcontractors, service providers) | Identification data, contact details, contractual data, bank details | Performance of the contract (art. 6-1-b); legal obligation (art. 6-1-c) | Duration of the relationship + 10 years |
| Compliance with legal and tax obligations (invoicing, accounting, filings) | Contractual and financial data | Legal obligation (art. 6-1-c of the GDPR) | 10 years (French commercial code); 6 years (art. L. 102 B of the French tax procedure code) depending on the document |
| Management of cookies and trackers | Technical identifier, browsing data | Consent (art. 6-1-a), except for strictly necessary cookies (exemption under art. 82 of the Informatique et Libertés act) | 13 months maximum for trackers subject to consent |
| Information system security and logging | Connection logs, IP address, technical data | Legitimate interest (security — art. 6-1-f); legal obligation (art. 6-II of the LCEN) | 12 months for connection data (decree no. 2011-219) |
| Protection of the contact form against automated submissions (reCAPTCHA) | Technical identifier, browsing behaviour data, IP address | Legitimate interest (security and prevention of abusive submissions — art. 6-1-f of the GDPR) | Period set by the service provider (Google); see its privacy policy |
| Online appointment booking with the AIC AIRPORTS team | Surname, first name, email address, selected time slot | Pre-contractual measures at the request of the data subject (art. 6-1-b of the GDPR) | Period set by the service provider (Microsoft); see its privacy policy |
Responding to contact or quotation requests (site form, email)
- Categories of data
- Surname, first name, job title, company name, email address, telephone, message
- Legal basis
- Pre-contractual measures at the request of the data subject (art. 6-1-b of the GDPR)
- Retention period
- 3 years from the last contact if the relationship does not materialise
Client relationship management (quotations, orders, invoicing, assignment follow-up)
- Categories of data
- Identification data, job title, business contact details, contractual and financial data
- Legal basis
- Performance of the contract (art. 6-1-b of the GDPR); accounting legal obligation (art. 6-1-c)
- Retention period
- Duration of the contractual relationship + 10 years (accounting and tax obligations, art. L. 123-22 of the French commercial code)
B2B commercial prospecting
- Categories of data
- Surname, first name, job title, business email address, telephone, company name
- Legal basis
- Legitimate interest of the controller (art. 6-1-f of the GDPR) — CNIL recommendation on B2B prospecting
- Retention period
- 3 years from the last contact initiated by the prospect
Supplier and partner management (subcontractors, service providers)
- Categories of data
- Identification data, contact details, contractual data, bank details
- Legal basis
- Performance of the contract (art. 6-1-b); legal obligation (art. 6-1-c)
- Retention period
- Duration of the relationship + 10 years
Compliance with legal and tax obligations (invoicing, accounting, filings)
- Categories of data
- Contractual and financial data
- Legal basis
- Legal obligation (art. 6-1-c of the GDPR)
- Retention period
- 10 years (French commercial code); 6 years (art. L. 102 B of the French tax procedure code) depending on the document
Management of cookies and trackers
- Categories of data
- Technical identifier, browsing data
- Legal basis
- Consent (art. 6-1-a), except for strictly necessary cookies (exemption under art. 82 of the Informatique et Libertés act)
- Retention period
- 13 months maximum for trackers subject to consent
Information system security and logging
- Categories of data
- Connection logs, IP address, technical data
- Legal basis
- Legitimate interest (security — art. 6-1-f); legal obligation (art. 6-II of the LCEN)
- Retention period
- 12 months for connection data (decree no. 2011-219)
Protection of the contact form against automated submissions (reCAPTCHA)
- Categories of data
- Technical identifier, browsing behaviour data, IP address
- Legal basis
- Legitimate interest (security and prevention of abusive submissions — art. 6-1-f of the GDPR)
- Retention period
- Period set by the service provider (Google); see its privacy policy
Online appointment booking with the AIC AIRPORTS team
- Categories of data
- Surname, first name, email address, selected time slot
- Legal basis
- Pre-contractual measures at the request of the data subject (art. 6-1-b of the GDPR)
- Retention period
- Period set by the service provider (Microsoft); see its privacy policy
Origin of the data
The data processed is:
- collected directly from the data subject (forms, email or telephone exchanges, contracts);
- obtained from lawful public sources (legal registers, professional websites, business directories) where it concerns B2B prospecting;
- passed on by an authorised third party (business introducer, partner), subject to the data subject having been informed beforehand.
Recipients of the data
Personal data is intended, strictly within the limits of their respective remits, for:
- authorised staff of AIC AIRPORTS;
- technical and operational processors acting for AIC AIRPORTS (host, email provider, chartered accountant, CRM tool, electronic signature platform where applicable), acting on instructions and under a contract compliant with article 28 of the GDPR — namely, by way of non-exhaustive illustration at the date of publication: Google Ireland Limited (reCAPTCHA anti-bot protection on the contact form) and Microsoft Ireland Operations Limited (online appointment booking module);
- administrative and judicial authorities and authorised public bodies (tax authorities, URSSAF, customs, etc.) in performance of a legal obligation or a judicial order;
- statutory auditors, legal and tax advisers, where applicable and on a contractual and professional basis.
The exhaustive and up-to-date list of technical processors may be provided on request at contact@aicairports.com.
AIC AIRPORTS does not sell, rent or trade personal data with third parties for marketing purposes.
Transfers of data outside the European Union
Data is in principle processed and stored within the European Economic Area (EEA).
Should any processor be required to process data outside the EEA (for example: email hosting, productivity tools), AIC AIRPORTS ensures that the transfer is covered by one of the mechanisms provided for in articles 44 to 49 of the GDPR: an adequacy decision of the European Commission, standard contractual clauses adopted by the Commission, binding corporate rules (BCR) or any other appropriate safeguard. The list of the processors concerned and of the applicable safeguards may be provided on request at contact@aicairports.com.
This is notably the case for the reCAPTCHA service (Google Ireland Limited, which may involve processing by its American parent company Google LLC) used on the contact form, and for the online appointment booking service (Microsoft Ireland Operations Limited, Microsoft group). Where they occur, these transfers are covered by the European Commission's standard contractual clauses, in accordance with the commitments made by those providers in their terms applicable to business customers.
Data security
In accordance with article 32 of the GDPR, AIC AIRPORTS implements technical and organisational measures appropriate to the risks, including:
- access control to information systems (authentication, strong passwords, principle of least privilege);
- encryption of connections to the site (HTTPS / TLS);
- regular data backups;
- selection of processors providing sufficient security guarantees (article 28 of the GDPR);
- awareness training and confidentiality undertakings for anyone accessing the data;
- an internal procedure for handling incidents and data breaches, compliant with articles 33 and 34 of the GDPR.
Rights of data subjects
In accordance with articles 12 to 22 of the GDPR and with the Informatique et Libertés act, any person whose data is processed has the following rights:
- Right of access (art. 15 of the GDPR):
- obtain confirmation that data concerning them is being processed and receive a copy of it;
- Right to rectification (art. 16):
- have inaccurate data corrected or incomplete data completed;
- Right to erasure (art. 17, the “right to be forgotten”):
- request the deletion of the data in the cases provided for by the regulation;
- Right to restriction of processing (art. 18):
- temporarily suspend the processing in the cases provided for;
- Right to data portability (art. 20):
- receive the data provided in a structured, commonly used and machine-readable format;
- Right to object (art. 21):
- object to processing based on legitimate interest, and object absolutely to commercial prospecting;
- Right to withdraw consent (art. 7-3):
- withdraw consent at any time where the processing is based on it;
- Right to give post-mortem instructions (art. 85 of the Informatique et Libertés act):
- determine what happens to their data after their death.
How to exercise these rights
These rights may be exercised at any time and free of charge, by sending a request:
- By email
- contact@aicairports.com — subject: “Demande RGPD”
- By post
- AIC AIRPORTS — 1, rue de l'abbé Grégoire, 91000 Évry-Courcouronnes, France
For security reasons, AIC AIRPORTS may request proof of identity before acting on a request, where there is reasonable doubt as to the identity of the person making it (art. 12-6 of the GDPR).
AIC AIRPORTS undertakes to respond within one month of receiving the request, a period which may be extended by two months given the complexity or the number of requests (art. 12-3 of the GDPR).
Lodging a complaint with the CNIL
In the event of a difficulty or a persistent disagreement about the processing of their data, the data subject has the right to lodge a complaint with the French data protection authority (CNIL):
- Address
- 3 place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07
- Telephone
- 01 53 73 22 22
- Website
- www.cnil.fr
Automated decision-making and profiling
AIC AIRPORTS does not carry out any solely automated decision-making producing legal effects concerning data subjects or similarly significantly affecting them within the meaning of article 22 of the GDPR.
Changes to this policy
This privacy policy may be amended at any time to reflect legislative, regulatory, case-law, technical or business developments at AIC AIRPORTS.
The version in force is the one published on the site on the date of consultation.
A question about this page?
Write to us at contact@aicairports.com: we answer every enquiry within 48 working hours.