RGPD
Internal data protection policy
Our internal framework for protecting personal data every day.
Management commitment
Evey France is committed to protecting the personal data it processes. Management has appointed a data protection officer: Noômen Lahimer, reachable at noomen.lahimer@evey.live.
Principles
We apply the GDPR principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality.
Access management
Access to personal data is restricted to authorised persons, limited to what their duties require. Each access is individual, authenticated and revocable.
Security
We implement appropriate technical and organisational measures: encrypted communications, authentication, backups, and providers offering GDPR-compliant safeguards.
Data breaches
Any personal data breach is documented. If it poses a risk to individuals, it is notified to the CNIL within 72 hours; affected individuals are informed when the risk is high.
Processors
We only engage processors providing sufficient guarantees, governed by a contract compliant with Article 28 of the GDPR.
Awareness
Everyone working for Evey France is made aware of data protection and bound to confidentiality.
Review
This policy is reviewed regularly and updated whenever our processing activities or the regulations change.