Personal data protection policy
Introduction
The Comexposium Group pays particular attention to the protection of personal data.
Compliance with this requirement is a fundamental element in building the relationship of trust that the Group intends to establish and maintain with the data subjects who entrust it with their data.
This personal data protection policy (hereinafter the "Policy") sets out the practices and conditions under which COMEXPOSIUM HEALTHCARE (hereinafter the "Company"), a subsidiary of the Group, processes your Personal Data.
COMEXPOSIUM HEALTHCARE is a French simplified joint-stock company (Société par Actions Simplifiée), registered with the Paris Trade and Companies Register under number 398 340 356, with a share capital of €7,622.45, whose registered office is located at 10 avenue de Messine, 75008 Paris, France. EU VAT number: FR92398340356.
Personal Data (hereinafter the "Data") means any information relating to an identified or identifiable natural person; an "identifiable natural person" is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; as this term is defined by applicable regulations.
Article 1 – what data is collected?
- Data relating to your identity: last name, first name, email address, postal address, telephone number and your profile (visitor, congress attendee, exhibitor, sponsor, partner, applicant).
- Data relating to your professional profile: medical specialty, position, company or place of practice, biography and, where applicable, the supporting documents used to verify your status as a healthcare professional, which are required to access certain content and certain congress badges.
- Data relating to your registration and participation in congresses: congress and edition concerned, dates of attendance, history of attendance at congresses and events organised by the Company.
- Data relating to your order: information necessary to fulfil and complete your order (e.g. congress registration), in particular information relating to the payment card used (cardholder name, card number, expiry date, etc.), the details and date of the order, and exchanges with the customer relations department. In any event, payment Data is processed in accordance with the applicable regulations and security standards.
- Data relating to login and use of your "My Account" account: username and password, preferences and interests (favourite topics), photograph, biography, history of congresses you have attended. In any event, the account is subject to specific terms of use.
- Data relating to your information requests via the contact section: we process your personal data to respond to requests submitted via the Website contact form. This data includes your name, your email address, the congress selected, your specialty and the information entered in the "How can we help you?" field.
- Data relating to your participation as an exhibitor or sponsor: company contact details, VAT number and proof of registration.
- Browsing data (for more information, see the cookie policy available on the Website): IP address, browser used, browsing time, search history, operating system, language and pages viewed.
- This Data is collected by means of cookies and other trackers, under the conditions set out in the cookie policy available on the Website.
- Cookies that are strictly necessary for the operation of the Website are placed on the basis of the Company’s legitimate interest. Non-essential cookies (in particular analytics and personalisation cookies, etc.) are placed only after the user’s consent has been obtained, in accordance with applicable regulations.
- Data relating to the use of social networks: when you interact with the social network features offered on the Website (Facebook, Instagram, LinkedIn, YouTube, etc.).
- These communications are governed by the personal data protection policies of those social networks, which we invite you to consult.
- Data relating to audience measurement of our emails: when we send you communications by email (congress programmes, news, newsletters), a measurement tag ("tracking pixel") may enable us to understand which content and news matter most to you, to improve the relevance and timing of what we send you, and to measure the performance of our communications, so that we can continue to improve them.
- Some processing is based on your consent. Where these tags are used to measure and analyse the performance of our communications, to adapt their content, frequency, timing or sending channel, to personalise the messages and invitations we send you, to build profiles for targeting purposes on other media, or to detect and analyse potential fraudulent use, they are based on your consent, which you may withdraw at any time.
- Other processing that does not require your consent. Some tags are strictly necessary and do not require your consent: those contributing to the security and authentication of our mailings; those measuring opens solely for deliverability purposes, limited to managing inactive recipients on our lists, for transactional emails or emails you have requested (registration confirmation, badge delivery); and the retention of a record of opening where this helps demonstrate compliance with a legal obligation to provide information.
- Pixels exempt from consent: Certain tags embedded in our emails do not require your consent, insofar as they are strictly necessary for the provision of a service you have requested or for compliance with our obligations. This covers pixels used for security and authentication purposes, pixels related to our transactional communications (registration confirmation, delivery of badge/ticket/invitation), those meeting a legal obligation or serving as evidence, and pixels used solely to measure the deliverability of our mailings and to identify inactive recipients. For this last purpose, only the date of the last day of opening is retained, excluding the time, and it is overwritten with each new opening. These tags are not used for any other purpose, in particular audience measurement, personalisation or targeting, which require your prior consent.
Article 2 – how is your data collected?
2.1. Depending on how you interact with the Company, the Company may collect your Data in the ways described below.
2.2. The Company collects your Data directly from you, in particular when you fill in a contact form, a congress registration form or an exhibitor/sponsor application form, place an order, or contact the Company (for example by sending it an email).
2.3. The Company collects your Data indirectly when you browse the Website, by means of cookies and trackers under the conditions set out above. The Company also collects your Data via third parties, including social networks, when you use the account you hold with those third parties to log in or register for an event.
The Company uses tags ("tracking pixels") embedded in its emails to measure and analyse your interactions with these communications. The purposes pursued, the data processed and the legal basis applicable to each are set out in Article 3.
2.4. When you provide Data to the Company, it is your responsibility to ensure that it is accurate and complete. Where necessary, you must update it or request that it be updated using the contact details given in Article 6.
Article 3 – why is your data collected?
Your Data is subject to automated processing carried out by the Company for the purposes described below, both in connection with your use of the Website and with your participation in events organised by the Company or whose organisation has been entrusted to it.
To make the processing carried out easier to understand, the table below summarises the purposes pursued, the categories of Data concerned and the associated legal bases.
| Purpose | Data category | Legal basis |
| Handling your requests | Data relating to your identity (last name, first name, email address, telephone number), content of the request. | The legitimate interest of the Company in responding to your request, or for pre-contractual reasons. |
| Management of your participation in events (visitors, exhibitors) and creation of your account | Data relating to your identity (last name, first name, email address, telephone number, position, company). | The performance of pre-contractual and/or contractual measures relating to the participation and registration of the data subject in the event organised by the Company. |
| Management of your order | Data relating to your order (e.g. congress registration), information relating to the payment card used (cardholder name, card number, expiry date, etc.), the details and date of the order, exchanges with the customer relations department. | The performance of pre-contractual and/or contractual measures relating to the participation and registration of the data subject in the event organised by the Company. |
| Management of your account | Data relating to login and use of your "My Account" account (username and password, preferences and interests, favourite topics, photograph, biography, history of congresses you have attended) | Legitimate interest |
| Improving the quality and organisation of events | Data relating to your identity (position, company, email address, telephone number), Data relating to login and use of the Account (type of event attended, date of attendance, mode of attendance). | The legitimate interest of the Company in improving the quality of the events it organises. |
| Sending information and commercial communications – professional prospects | Identity data (last name, first name), professional data (position, company), contact data (email, telephone number). | The legitimate interest of the Company in promoting the events it organises to a professional audience. |
| Sending communications about other Group entities or partners | Data relating to your identity (last name, first name, position, company, email address, telephone number). | Your consent and/or legitimate interest |
| Personalising and optimising your experience and carrying out statistical analyses | Browsing data, Data relating to login and use of the Account (your preferences). | Your consent and/or legitimate interest |
| Measuring the audience and performance of our communications (open rates, campaign optimisation) | Data relating to audience measurement of our emails: opening (date and time), date of the last email opened, and the profile and interests inferred from them. | Your consent. |
| Personalisation and profiling (adapting content, frequency, timing and sending channel; scoring) | Data relating to audience measurement of our emails: opening (date and time), date of the last email opened, and the profile and interests inferred from them. | Your consent. |
| Detecting and analysing fraudulent use | Data relating to audience measurement of our emails: opening (date and time), date of the last email opened, and the profile and interests inferred from them. | Your consent. |
Article 4 – who receives your data?
4.1. Your Data is processed by the Company’s internal teams (Marketing, Sales, Web departments). In addition, only service providers and their specifically authorised staff are permitted to access your Data, and solely in view of the specific services entrusted to them, which they must perform exclusively on behalf of the Company in strict compliance with obligations, in particular of security and confidentiality.
4.2. With your consent where required, your Data may be passed on to entities of the Comexposium Group to which the Company belongs, as well as to partners, in particular so that they can send you information and news about the services and products they offer.
4.3. Where required by applicable regulations, the Company may disclose your Data to bodies and authorities legally authorised to access it (in particular judicial and administrative authorities).
Article 5 – how is your data protected?
- Access to data is strictly limited to authorised persons, who are bound by a duty of confidentiality;
- Service providers and subcontractors, when we use their services, are contractually bound to comply with security obligations;
- Your personal data is stored on servers offering all security guarantees.
Article 6 – what are your rights?
6.1. In accordance with applicable regulations and under the conditions they define, you may at any time exercise your:
- Right of access: you may ask the Company for information about the processing of Data concerning you and for a copy of that Data.
- Right to rectification: you may request the rectification of inaccurate Data concerning you where the Data held by the Company is incorrect or incomplete.
- Right to erasure (right to be forgotten): you have the right to obtain from the Company the erasure of your Data where one of the grounds provided for by the regulations applies (Data no longer necessary, withdrawal of your consent for processing based on consent, etc.).
- Right to object: you have the right to object at any time, on grounds relating to your particular situation, to the processing of your Data, including for direct marketing purposes. With regard to audience measurement of our emails, which is based on your consent, you may withdraw that consent at any time, as indicated in our emails or by contacting us using the details given in this article.
- Right to portability of your Data: you have the right to receive your Data in a usable format.
- Right to restriction of processing : you may ask the Company to suspend the processing of your Data where one of the grounds provided for by the regulations applies (contesting the accuracy of the data, etc.).
- Right not to be subject to automated decision-making : you may refuse a decision taken solely by a machine, without human intervention.
- Right to issue post-mortem instructions: Under the conditions defined by the regulations, you also have the right to set general or specific instructions regarding what happens to your Personal Data after your death.
6.2. Where your Data is processed on the basis of your consent, you may withdraw it at any time. Please note, however, that processing carried out before such withdrawal will remain valid.
6.3. How to exercise your data protection rights
- Via our online form
- By email at: data-privacy@imcas.com;
- By using the rights request form made available to you on the Website:
- By post at the following address: COMEXPOSIUM HEALTHCARE — Privacy, 10-12 avenue de Messine, 75008 Paris, France.
Article 7 – how long do we keep your data?
7.1. The Company retains your Data for no longer than is necessary for the purposes set out in this Policy. Beyond that period, your Data may be archived in order to comply with the legal obligations to which the Company is subject, or deleted.
7.2. Data used to establish proof of a right or a contract, or retained by the Company in order to comply with a legal obligation, is archived in accordance with the provisions in force (in particular the accounting obligations laid down in the French Commercial Code).
7.3. The Company takes into account the seasonality of the congresses it organises and the nature of its relationship with you (prospect, congress attendee, exhibitor, sponsor, etc.). The applicable retention periods are set out below:
| Data category | Retention period |
| Prospect data | 3 years after the last contact |
| Customer data | The entire term of the service contract, plus 5 years after its termination. |
| Data relating to your orders and invoicing | Invoicing data is retained for 10 years in accordance with the provisions of the French Commercial Code. |
| Data relating to requests you make when contacting us | The time needed to process and close the request. |
| Data relating to your subscription to the professional newsletter | 3 years from the last active contact, or until consent is withdrawn or the right to object is exercised. |
| Website browsing data (cookies and trackers subject to consent) | 13 months maximum from the placement of the tracker. |
| Data relating to the use of social networks | Data processed via social networks is subject to the retention policies of those platforms. |
| Bank data (card number and expiry date) | 13 months after the debit date (15 months for deferred debit cards) |
| Card security code (CVV) | The duration of the transaction |
| Pixel-related data | 36 months from the placement of the tracker |
Article 8 – data transfers
For the hosting and processing of your Data, the Company favours resources located within the European Union: the Website is hosted by AWS France (52 rue du Port, 92000 Nanterre, France).
However, since some IMCAS congresses are held outside the European Union (in particular in Asia and the Americas) and the Company may use international service providers, a transfer of Data to a country outside the European Union may be envisaged. In such a case, the Company undertakes to ensure that appropriate technical and organisational measures are put in place, in particular the use of the standard contractual clauses adopted by the European Commission or any other safeguard recognised as equivalent by applicable regulations.
Article 9 – changes to the data protection policy
9.1. Any change made by the Company to this Policy will be published as an update on the Website.
9.2. Users are invited to consult this Policy regularly in order to be aware of any updates or changes.
9.3. If any clause of this Policy is declared void or contrary to regulations, it shall be deemed unwritten but shall not render the other clauses of the Policy void.