Privacy policy
This Privacy Policy is effective as of January 06, 2024
7. PERSONNAL DATA
7.1. General Information
In all cases where they are mentioned with capital letters, the terms of this Article refer to the definitions provided by the Law and the GDPR.
The Company declares and guarantees that when acting as the Data Controller, it processes the Member's Personal Data in compliance with the Law and the Regulation and its Privacy Policy available on the Website.
7.2. Processing Objectives
7.2.1. Personal data processed by the Company under the conditions provided by the Law and Article 6.1b of the GDPR (execution of the contract).
The Company will carry out the processing of personal data necessary to execute the Regulation and the Iamfashion Program.
The purposes of the processing of personal data carried out by the Company are as follows:
• Implementation and monitoring of Services, including consultations of methodological contents,
• Monitoring and management of customer relationships (billing, commercial management, archiving, telephony, improvement of the quality, security, and performance of Services.
The Company undertakes not to use the data collected for purposes other than those mentioned above.
The personal data processed consists of the following information: title, first name, last name, email address, mobile and work phones, job title, and department of the Member's collaborators, Access Codes, website address, and/or social media accounts of the Member. This data is retained by the Company for the entire duration of the Member's membership in the Iamfashion Program and for sixty (60) months thereafter in pseudonymized form for evidentiary purposes. In the context of recording group calls as defined in Article 4.3.1 above, the Company also processes the voice and, if applicable, the image of the Member.
This processing is carried out for the purpose of executing the Services and training the Members. The recipients of this personal data are the entire community and individuals responsible for executing the Services on behalf of the Company. The retention period for these recordings is limited to one (1) year from their capture, considering the duration of the Iamfashion Program and the recurrence of questions that may be posed by Members regarding the Iamfashion Program.
As part of the purposes defined above, the Member accepts that the aforementioned personal data concerning them may be transferred by the Company to its subcontractors involved in the execution of the Iamfashion Program.
Personal data collected and processed by the Company to comply with its legal obligations are retained in accordance with applicable law, including the prescription period applicable to civil, tax, or criminal actions.
7.2.1.1. Personal data processed by the Company under the conditions provided for by the Law and Article 6.1a (Consent of the data subject).
Subject to the consent of the Member, the personal data concerning them may be subject to automated processing by the Company in accordance with the provisions of the Law and Article 6.1.a) of the GDPR, for the purpose of sending the Company's newsletter, prospecting, informing about new services and the Company's news, and promoting its business and the Iamfashion Program. The personal data collected and processed are retained for the duration of the Member's consent for this purpose.
7.2.2. Categories of Data Subjects and Recipients
The categories of individuals affected by the processing carried out by the Company are Members, and, if applicable, their various users.
The recipients of this data include the Company's management, its technical services, its communication and marketing services, any subcontractors, as well as accountants and all external advisors bound by confidentiality obligations in the exercise of their duties, organizations, legal auxiliaries, and ministerial officers in the context of debt collection missions?
7.2.3. Analysis of Personal Data
The Member accepts that the Company may, in its legitimate commercial interest, collect, retain, and use the Member's personal data generated and stored during their access to the Services and their use for the purpose of:
- Conducting research and development to improve the Site and the Iamfashion
Program.
- Developing and providing existing and new Service and features.
In this context, the Company ensures that the collected information is processed in a pseudonymized manner and is displayed only as a whole and not linked to the Member.
7.2.4. Personal
The Company commits to:
- Take all reasonable measures to ensure that every employee with access to personal data complies with their obligations under the Regulation;
- Ensure that access to personal data is strictly limited to employees who need it
exclusively for the execution of the Regulation or the Iamfashion Program;
- Ensure that authorized employees processing personal data have committed to maintaining its confidentiality or are bound by an appropriate legal obligation of confidentiality.
If applicable law requires it, the Company will appoint a data protection officer and provide information related to such appointment.
7.2.5. Security and Audit
The Company takes all organizational and technical measures, as well as necessary precautions, to preserve the security and confidentiality of the personal data it processes, particularly to prevent data from being distorted, damaged, or accessed by unauthorized third parties.
The Company commits to implementing and/or ensuring the following measures are in place:
- physical security measures to prevent unauthorized access to servers where personal data is stored;
- identity and access controls through an authentication system and a password policy;
- a permissions management system to limit access to the physical location where personal data is physically stored to only those individuals who need access within the scope of their roles and responsibilities;
- security personnel responsible for the physical security of locations where personal data is stored;
- logical isolation of Members from each other,
- user and administrator authentication processes, as well as measures to protect administrative function,
- processes and devices for tracking all actions performed on its information system and for conducting reporting actions in compliance with prevailing regulations in the event of incidents affecting personal data.
The Member is responsible for the security of their own information system, including resources, systems, and applications. This includes implementing measures such as firewalls, access rights management, resource configuration, etc. The Company will not be held responsible for security incidents related to the use of the internet, including loss, alteration, destruction, disclosure, or unauthorized access to data or information from its infrastructure or that of the Member.
7.2.6. Violation of Personal Data
The Company will notify the Member if it becomes aware of a breach of security rules resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure to a third party of personal data, or unauthorized access to such data, resulting from an act or omission on the part of the Company or its subsequent subcontractors.
7.2.7. Transfer of Personal Data outside the European Union
The Member accepts that access to the Site and the execution of the Services may involve the processing of personal data by subcontractors in countries located outside the European Union. However, the Company will not transfer personal data outside the European Union to a subsequent subcontractor without the prior written consent of the Member unless such transfer is subject to: (a) an adequacy decision (in accordance with Article 45 of the GDPR); or (b) appropriate safeguards (in accordance with Article 46 of the GDPR); or (c) binding corporate rules (in accordance with Article 47 of the GDPR).
7.2.8. Rights of the Member and Data Subjects
The Member has the right to be informed, access, rectify, and delete data, the right to request the limitation of processing, the right to object to processing, and the right to data portability concerning themselves. They can exercise these rights and obtain information by emailing the Company at the email address hello@iamfashionglobal.com.
The Member is informed that they have the right to lodge a complaint with the French Data Protection Authority (CNIL).





