Privacy Policy
As part of its activities, Nemorius, in its capacity as Data Controller, may process the personal data of users of the website accessible at the URL www.nemorius.com
This Privacy Policy is intended to inform you of Nemorius’s policy regarding the protection of personal data and the rights you have, in accordance with the provisions of European Union Regulation (EU) 2016/679 of April 27, 2016, known as the General Data Protection Regulation (“GDPR”), as well as the latest version of Law No. 78-17 of January 6, 1978, on Information Technology, Data Files, and Civil Liberties (hereinafter “applicable regulations”).
1. Definitions
For the purposes of and to ensure a proper understanding of this policy, the following terms and definitions apply:
“Cookies”: Refers to all devices falling within the scope of the regulations, that is, “any operation intended to access, by means of electronic transmission, information already stored in the terminal equipment of a subscriber or user of an electronic communications service, or to store information therein.”
“Personal Data” or “Data”: Any information that allows a natural person to be identified or made identifiable, directly or indirectly.
“Data Protection Officer” or “DPO”: Refers to the natural person or legal entity whose primary responsibility is to oversee Nemorius’s compliance with the GDPR.
“Data Controller”: This refers to the natural person or legal entity (represented by its legal representative) that, alone or jointly with others, determines the purposes and means of processing personal data.
“Processor”: Refers to the service provider contractually bound to Nemorius that processes personal data on behalf of and/or pursuant to the instructions of Nemorius, acting as the Data Controller.
“Processing”: Any operation or set of operations performed, whether or not by automated means, on personal data or sets of personal data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
2. Purposes of Data Processing Carried Out by Nemorius
As the Data Controller, Nemorius collects and uses users’ personal data for the purposes of its business activities when:
- The processing is necessary for the performance of a contract to which you are a party or for the implementation of precontractual measures taken at your request. This applies to the following purposes:
- Creating an account on our platform or modifying your account settings;
- Logging in with your account on our website or when using our application programming interface (API).
- Processing is necessary for the purposes of Nemorius’s legitimate interests:
- Receiving and processing contact requests you submit via our Site, in order to respond to your inquiries and provide you with information about products or answer your questions related to Nemorius.
Our website also uses cookies for various purposes, which are detailed in our cookie policy (with a hyperlink to the cookie policy).
In accordance with applicable regulations, all processing of personal data carried out by Nemorius is recorded in its Register of Processing Activities.
3. Data Collected by Nemorius
As part of the aforementioned processing activities, Nemorius processes the following categories of personal data:
- Identity data: your name, email address, and phone number.
- Technical data: technical information, including the Internet Protocol (IP) address used to connect your computer to the Internet, your login information, authentication information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, frequency of app use, and other performance data.
- Usage data: information about the links you wish to shorten, including the full Uniform Resource Locators (URLs) to be shortened.
We do not require or collect any sensitive personal data unless you choose to provide us with such information. This information will not be retained unless necessary for the processing of your request.
Your personal data is collected both passively and actively.
- Passive collection: Information regarding your use of our Website is automatically collected when you interact with its features. To do this, we use “cookies” to collect information about visitors. Cookies are small files that are stored on any communication device used by the user (e.g., computer, phone, and tablet) when they browse the Website. These files enable the exchange of status information between the Website and the user’s device. You can configure your preferences regarding cookies using the cookie banner. However, certain cookies are necessary for the Website’s operation and security and cannot be disabled.
- Active Collection: We collect data directly from you when you provide information through our Website. If you do not wish for your personal data to be processed, please do not provide it. However, when this information is necessary for the provision of our services and you refuse to provide it, you will not be able to benefit from said services. Furthermore, the information collected directly through our contact forms indicates whether responses are optional or required by means of an asterisk (*), in accordance with the principle of data minimization. If required information is not provided, Nemorius will not be able to provide the expected information or services.
4. Recipients of the Data
The personal data collected and processed is intended for the duly authorized departments of Nemorius and its processors and partners.
Furthermore, Nemorius ensures that its data processors and partners provide sufficient safeguards regarding data security and confidentiality.
In the course of its business, Nemorius may use data processors or partners located outside the European Union. Nemorius ensures that such transfers of personal data are made to countries recognized as providing an adequate level of protection for your personal data, or that provide appropriate safeguards in accordance with applicable regulations, such as standard contractual clauses approved by the European Commission, for example.
5. Data Retention Periods
Your personal data is retained only for as long as necessary to fulfill the purposes described above, and in compliance with applicable legal and regulatory provisions.
Thus, your personal data is retained for the following periods:
- Duration of the contract
6. Data Security
Nemorius is committed to protecting and securing the personal data you have chosen to provide, and has implemented appropriate technical and organizational measures to prevent any unauthorized access, use, modification, destruction, loss, damage, or disclosure of the data. In particular, Nemorius holds ISO 27001 certification.
In the event of a data breach, Nemorius undertakes to notify the French Data Protection Authority (CNIL), as required by applicable regulations, within the prescribed time limits.
Furthermore, if Nemorius determines that a personal data breach poses a high risk to your rights and freedoms, Nemorius will inform you as soon as possible.
7. Rights of Data Subjects
In accordance with applicable data protection regulations, you have several rights that you may exercise at any time:
- The right of access;
- The right to rectification;
- The right to erasure;
- The right to object;
- The right to restrict processing;
- The right to data portability (where applicable);
- The right to deletion;
- The right to withdraw your consent (if applicable).
You may exercise your rights directly with Nemorius’s Data Protection Officer:
- By email at the following address: dpo@nemorius.com
- By mail at the following address: 54 rue Saint-Maur, 75011 Paris
You may also file a complaint with the French Data Protection Authority (CNIL) via its website https://www.cnil.fr/fr/plaintes and/or at the following mailing address: CNIL - 3 Place de Fontenoy – TSA 80715 - 75334 PARIS CEDEX 07.
8. Hyperlinks
The website may contain hyperlinks to social media platforms, including LinkedIn, as well as to other third-party services. When the user clicks on these links, they are redirected to external websites where the processing of personal data is governed by those sites’ own privacy policies. Users are strongly advised to carefully review these policies before interacting with these platforms.
Please note that accessing these third-party sites may result in the collection and processing of personal data by such sites, including the user’s IP address, browsing data, as well as any other technical identifiers or information voluntarily provided by the user in connection with their use of such services.
Such processing may, where applicable, involve the transfer of personal data to countries outside the European Union, where the level of data protection may differ from that in effect within the European Union.
In any event, Nemorius has no control over the methods used by these third-party sites to collect, use, store, and transfer personal data. Nemorius shall not be held liable for the processing carried out by such third parties, which act as independent data controllers.
9. Cookies
For more information about the cookies used on our website, please see our Cookie Policy.
You may update your cookie settings at any time to change your choices regarding acceptance or rejection.
10. Revision of the Privacy Policy
This Privacy Policy may be updated at any time, particularly in light of changes in applicable laws and regulations regarding the protection of personal data. As such, we encourage you to review it regularly.