Privacy policy
RDMC processes personal data of visitors, prospects, customers, partners, suppliers, candidates and users of its services.
Data controller
| Entity | RDMC SAS |
| Address | 1 rue de la Destinée, 95800 Cergy, France |
| SIREN | 880 905 088 |
| SIRET | 880 905 088 00014 |
| VAT number | FR37 880 905 088 |
| D‑U‑N‑S | 273969130 |
| Contact | privacy@rdmc.fr |
Data processed
- identity and professional contact details;
- role, company and business relationship;
- requests, tickets and correspondence;
- contractual, billing and payment data;
- technical logs, IP address, device and timestamp;
- application / recruitment data;
- data entrusted by customers when RDMC acts as a processor.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Requests and proposals | Pre-contractual steps and legitimate interest |
| Contracts and services | Performance of the contract |
| Billing | Legal obligation |
| Security | Contract and legitimate interest |
| Optional cookies | Consent |
Data retention periods
RDMC applies the principle of storage limitation. Personal data is retained for no longer than is necessary for the purposes for which it was collected and processed.
Some data may nevertheless be placed in intermediate archiving where a legal or regulatory obligation so requires, or where retention is necessary for the establishment, exercise or defence of legal claims.
Applicable periods
| Data category | Retention period |
|---|---|
| Contact and information requests | For as long as needed to handle the request, then for up to 3 years from the last contact where a business relationship may continue. |
| Prospects and commercial relationships | For up to 3 years from the last contact with the prospect, unless the data subject objects or a specific obligation justifies a different period. |
| Customer and contractual data | For the entire duration of the contractual relationship, then archiving of necessary data for the applicable legal retention or limitation periods. |
| Invoices, orders and accounting records | 10 years from the close of the relevant financial year, in accordance with applicable legal obligations. |
| Support tickets and assistance requests | For as long as needed to handle and follow up the request, then for the duration of the contractual relationship. Evidence required to establish proof or to defend RDMC’s rights may then be placed in intermediate archiving for the applicable limitation periods. |
| Technical logs, security logs and connection data | A maximum of 12 months from recording, unless a legal or regulatory obligation requires a different period. |
| Recruitment / application data | For the duration of the recruitment process and, where retention is justified, for up to 2 years after the last contact with the candidate, unless an erasure request or applicable objection applies. |
| Optional cookies and trackers | According to the period applicable to the tracker concerned and in line with the rules set out in the Cookie and consent policy. |
| Data processed on behalf of customers | For the period defined by the customer, acting as controller, in accordance with the contract and its documented instructions. |
| Data relating to an incident, dispute or litigation | For as long as needed to handle the incident or dispute and, where necessary, until the applicable limitation periods and remedies expire. |
Technical logs generated by the systems, applications, servers, hosting infrastructure, network equipment and security devices operated by RDMC are retained for a maximum of 12 months from recording.
They may notably include IP addresses, timestamps, technical identifiers, authentication events, access and connection traces, as well as system, network, application or security events.
Purposes of logging
- information systems security;
- infrastructure and service monitoring;
- detection, analysis and handling of incidents;
- diagnosis and remediation of malfunctions;
- traceability of access and operations;
- detection and prevention of unauthorised access, abuse and attack attempts;
- maintaining operational (MCO) and security (MCS) conditions.
At the end of the retention period, the relevant logs are deleted or anonymised, unless a legal or regulatory obligation, judicial proceedings, a request from a competent authority, or the need to establish, exercise or defend a legal claim justifies retention for an additional period.
Technical connection data subject to a specific legal or regulatory regime, in particular in the context of electronic communications activities, may be subject to distinct retention periods and arrangements.
Data processed on behalf of our customers
Where RDMC acts as a processor within the meaning of the GDPR, the retention period for data processed on behalf of the customer is determined by the customer, acting as controller.
RDMC processes and retains such data in accordance with the customer’s documented instructions, the applicable contractual terms and the legal and regulatory obligations to which RDMC is subject.
At the end of the service or upon the customer’s instruction, the data is, depending on the applicable contractual terms, returned, deleted or anonymised, subject to any legal obligations requiring retention.
Deletion, anonymisation and archiving
At the end of their active retention period, data is, depending on its nature and applicable obligations:
- securely deleted;
- irreversibly anonymised; or
- placed in intermediate archiving, with access limited to authorised persons only, where a legal or regulatory obligation or the defence of RDMC’s rights justifies retention.
Archived data is no longer used for the operational purposes that justified its initial collection.
Data that has been effectively and irreversibly anonymised so that it no longer allows a natural person to be identified directly or indirectly may be retained for statistical, technical, security or service-improvement purposes.
Criteria for determining retention periods
Where no specific period is imposed by law or regulation, RDMC determines the appropriate retention period taking into account in particular:
- the purpose for which the data was collected;
- the duration of the contractual or commercial relationship;
- the nature and sensitivity of the data;
- applicable legal and regulatory obligations;
- limitation periods;
- security and traceability requirements;
- needs related to the prevention, detection and investigation of incidents;
- any need to establish, exercise or defend legal claims.
RDMC periodically reassesses the retention periods applied to ensure they remain necessary, proportionate and suited to the purposes pursued.
Hosting and infrastructure
This website is hosted and operated by RDMC SAS, which provides administration, operational maintenance and supervision of the hosting infrastructure.
The technical infrastructure used by RDMC relies on computing resources located in OVHcloud data centres in France. OVHcloud acts as an infrastructure and data centre provider.
Recipients and transfers
Data is accessible to authorised RDMC personnel and to necessary service providers. Transfers outside the European Economic Area are framed by a GDPR-recognised mechanism.
Rights
You may exercise the rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent where those rights apply to the processing concerned.
Requests should be sent to privacy@rdmc.fr. You may also lodge a complaint with the CNIL.