Personal Data Protection Policy

1. Purpose
The purpose of this policy is to define the principles and commitments of the
company ALLIANC3, whose registered office is located at 59 rue de Ponthieu 75008 Paris, incorporated
as a SAS (Société par Actions Simplifiée, a simplified joint-stock company), registered with the Trade
Register of PARIS under SIREN number 930 289 327, in the context of its
consulting and technical assistance services, with regard to the protection of
personal data, in accordance with the applicable regulations,
in particular the General Data Protection Regulation (GDPR).
2. General principles
The company undertakes to ensure that the processing of personal data
carried out in the context of its consulting and technical assistance services is
performed in compliance with the rights and freedoms of data subjects, and in accordance with
the following principles:
- Lawfulness, fairness and transparency: data are collected and processed in a
lawful, fair and transparent manner with regard to the data subject.
- Purpose limitation: data are collected for specific, explicit
and legitimate purposes, related to the consulting and technical assistance
services, and are not further processed in a manner incompatible
with those purposes.
- Data minimisation: only the data strictly necessary for the
achievement of the purposes are collected and processed.
- Accuracy: data are kept up to date and measures are taken to ensure
that inaccurate data are erased or rectified.
- Storage limitation: data are retained for a
period not exceeding that necessary in view of the purposes pursued and
the contractual or legal requirements applicable to the consulting
and technical assistance services.
- Security and confidentiality: appropriate technical and organisational
measures are implemented to guarantee the security and confidentiality
of the data, in particular within the information systems and
tools used.
 
3. Rights of data subjects
The company guarantees data subjects the exercise of their rights, including:
- The right of access, rectification, erasure and restriction of processing;
- The right to withdraw their consent at any time where the processing is
based on consent;

- The right to lodge a complaint with the competent supervisory authority.
The procedures for exercising these rights are set out in the company’s
information notices and privacy policy. A point of contact
(Data Protection Officer or designated contact) has been identified to assist
individuals in exercising their rights.
4. Obligations of employees and subcontractors
The company’s employees and subcontractors undertake to comply with the principles
of data protection and to process personal data solely
within the scope of the purposes defined by the consulting and technical assistance
services. Any subcontracting is governed by a contractual framework guaranteeing
a level of protection equivalent to that of the company.
5. Data security
The company implements appropriate technical and organisational measures
to ensure the security, integrity and confidentiality of personal
data, in particular against destruction, loss, alteration, unauthorised
disclosure or unauthorised access, taking into account the specific features of the IT
systems and tools used.
6. Data retention and destruction
The data retention period is defined according to the purposes of the
processing, the contractual requirements and the legal obligations applicable to the
consulting and technical assistance services. At the end of this period, the
data are deleted or securely destroyed.
7. Notification of data breaches
In the event of a personal data breach, the company undertakes to notify
the competent supervisory authority and, where applicable, the data subjects, within
the statutory time limits and in accordance with the defined internal procedures, in connection with the
consulting and technical assistance services.
8. Awareness
ALLIANC3’s employees receive regular awareness training on best practices
for personal data protection and information security,
particularly in the context of IT technical assistance and
digital marketing services. They are also subject to an IT Charter setting out
the rules for using the company’s information systems and
digital tools.
9. Updating of the policy

This policy is reviewed and updated regularly in order to ensure its
compliance with the regulations, changes in the company’s practices and the
specific features of the consulting and technical assistance services.