Note: To receive updates made to this notice, please subscribe by clicking on the "Subscribe" button.
Hosting and processing of personal data
In accordance with the Terms and Conditions and / or the Terms of Services of the offer subscribed by the Customer, the Customer has given Compilatio his written and general permission to subcontract the processing of personal data to subcontractors and / or later subcontractors.
The list of subcontractors and/or later sub-processors and the processing operations concerned is shown in the table below:
Processing of personal data outsourced in whole or in part to third parties |
Identity of the subcontractor (for Studium and/or Copyright users) | Identity of the subcontractor (for Magister users) | Location of personal data | Additional information |
Compilatio account creation |
SAS OVH | / | France | Learn more: https://www.ovh.co.uk/personal-data-protection/ |
MAILJET INC. | / | European Union | Learn more: https://www.mailjet.com/legal/privacy-policy/ | |
SAS 1D345 | SAS 1D345 | France |
Learn more: |
|
Order Management | SAS OVH | / | France | Learn more: https://www.ovh.co.uk/personal-data-protection/ |
STRIPE PAYMENTS EUROPE LIMITED | / | Outside the European Union |
The similar level of protection is ensured by: standard contractual clauses (in accordance with the new version of June 4, 2021 of the European Commission) Learn more: |
|
Delivery of the service of Detection and Measurement of Similarities in texts in digital format, with others freely accessible and consultable on Internet / Fraud prevention in accessing and using the Service |
SAS OVH | SAS OVH | France | Learn more: https://www.ovh.co.uk/personal-data-protection/ |
SAS 1D345 | SAS 1D345 | France |
Learn more: |
|
Request for assistance on the service | ZENDESK INC. | ZENDESK INC. | European Union | Learn more: https://www.zendesk.fr/company/privacy-and-data-protection/ |
SAS OVH | SAS OVH | France | Learn more: https://www.ovh.co.uk/personal-data-protection/ | |
SAS 1D345 | SAS 1D345 | France |
Learn more: |
|
GOOGLE LLC | GOOGLE LLC | European Union | Learn more: https://cloud.google.com/terms/cloud-privacy-notice | |
Customer support Customer relationship management | ZOHO CORP. | ZOHO CORP. | European Union | Learn more: https://www.zoho.com/privacy.html |
GOOGLE LLC | GOOGLE LLC | European Union | Learn more: https://cloud.google.com/terms/cloud-privacy-notice | |
Infoplag |
/ |
SAS OVH |
France | Learn more: https://www.ovhcloud.com/en-gb/personal-data-protection/ |
/ |
SARL ALPAWEB |
France and Switzerland (suitable countries) | Learn more: https://www.alpaweb.com/mentions-legales-6.html | |
Training |
/ |
ZOHO CORP. |
European Union | Learn more: https://www.zoho.com/privacy.html |
/ |
GOOGLE LLC |
European Union | Learn more: https://cloud.google.com/terms/cloud-privacy-notice | |
Webinar |
/ |
ZOHO CORP. |
European Union |
Learn more: https://www.zoho.com/privacy.html |
/ |
GOOGLE LLC |
European Union | Learn more: https://cloud.google.com/terms/cloud-privacy-notice | |
Accounting |
STRIPE PAYMENTS EUROPE LIMITED | / | Outside the European Union |
The similar level of protection is ensured by: standard contractual clauses (in accordance with the new version of June 4, 2021 of the European Commission) Learn more: https://stripe.com/fr/privacy-center/legal#data-transfers |
/ | ZOHO CORP. | European Union | Learn more: https://www.zoho.com/privacy.html | |
Tracking your interest and exploring products and services associated with Studium and Copyright, for individual use | ZOHO CORP. | ZOHO CORP. | European Union | Learn more: https://www.zoho.com/privacy.html |
GOOGLE LLC | GOOGLE LLC | European Union | Learn more: https://cloud.google.com/terms/cloud-privacy-notice | |
Discover the other products offered by Compilatio | ZOHO CORP. | ZOHO CORP. | European Union |
Learn more: https://www.zoho.com/privacy.html |
GOOGLE LLC | GOOGLE LLC | European Union |
Learn more: https://cloud.google.com/terms/cloud-privacy-notice |
|
Information on the topic of plagiarism | ZOHO CORP. | ZOHO CORP. | European Union | Learn more: https://www.zoho.com/privacy.html |
GOOGLE LLC | GOOGLE LLC | European Union | Learn more: https://cloud.google.com/terms/cloud-privacy-notice | |
Storage of credit card information to facilitate future orders | STRIPE PAYMENTS EUROPE LIMITED | / | Outside the European Union |
The similar level of protection is ensured by: standard contractual clauses (in accordance with the new version of June 4, 2021 of the European Commission) |
At least 15 calendar days in advance, Compilatio informs the Customer of any planned changes regarding the addition or replacement of subcontractors and / or subcontractors later by amending upstream the list in the table presented above.
Data security
In order to ensure a level of security that is suitable for the type of data and for the risks of users' rights and freedoms being infringed, Compilatio SAS has implemented the following measures:
-
Technical
-
Restricted access to servicces via individual accounts requiring login and password
- Regularly updated password policy in line with CNIL and ANSSI recommendations
- Restricted SSH server access via login and password
- Time limit on attempts to access a service user account
- System that blocks the IP address of a user who has made too many failed attempts
- Daily backup of databases
- Daily backup of web servers
- Clustering the database containing user documents
- TLS encryption, at least in version 1.2, of client/server communications (https)
- Encrypting server/server communications
- Monitoring servers with automatic error reporting
- Server incident management protocol
- Automatic session locking procedure in case of inactivity for all Compilatio staff
- Implementation of a WPA2 (or WPA2-PSK) protocol for Wi-Fi networks by Compilatio
- Use of antivirus software by all Compilatio staff
- Installation of a state-of-the-art software firewall by all Compilatio staff
- Installation of a server logging system
- Protection of logging equipment by partitioning and logging information;
- Securing remote access to servers by Compilatio staff using VPN for mobile computing devices
-
-
Organizational
-
Training and awareness of Compilatio staff with access to personal data in personal data law
-
Training of all Compilatio staff in IT security via ANSSI training
-
Definition of clearance profiles for Compilatio staff with access to personal data
-
Removal of obsolete access permissions
-
Restriction of building access by badge
- Confidentiality clause for all Compilatio staff
-
Implementation of an IT charter
-
Establishment of procedures for notification of personal data breaches;
For more information on Compilatio Magister and Compilatio Magister+ services, please consult the CSA STAR CAIQ v4.0.2 self-assessment report, available at:
https://cloudsecurityalliance.org/star/registry/compilatio
-
This article has been translated by automatic software.