Privacy policy

Personal Data Protection Policy

Who are we and who does this policy apply to?

This Personal Data Protection Policy defines how our company, Ofelia (Bonitasoft), a SAS (simplified joint-stock company) with a share capital of €170,871.25, having its registered office at 60 rue François 1er, 75008 Paris (France), registered with the Paris Trade and Companies Register (RCS) under number 512854514 (hereinafter, "We" or "Ofelia"), processes your personal data.

It applies to any user of our products, solutions and websites (the "Solutions"), whether you have entered into a contract with us directly or you use our Solutions as an employee of one of our clients or as a member of one of our communities (hereinafter, "You" or the "Users").

In connection with the use of our Solutions, we may collect some of your personal data, acting either as a data controller or as a data processor.

This Personal Data Protection Policy defines our practices with regard to the collection, processing and retention of personal data, in accordance with the General Data Protection Regulation (GDPR) and any applicable regulations.

Why do we process your data?

Certain features of our Solutions require the processing of your personal data, including to create your user account, download the free versions of our products, access certain sections, or enable us to provide you with support and tailored services.

When you use our Solutions, Ofelia may carry out the following processing operations as a data controller within the meaning of Article 4 of the GDPR:

Processing necessary for the performance of a contract entered into between Ofelia and the User

  • Management of client relationships;
  • Management of support requests;
  • PS Consulting (custom developments on the Ofelia platform);
  • Management of client improvement requests;
  • Management of platform updates;
  • Training of users in the use of the platform;
  • Management and selection of partners;
  • B2B invoicing.

The retention period for data used in connection with the above processing operations corresponds to the term of the contract entered into between Ofelia and the User, unless a specific legal provision applies.

Management of the Ofelia community (formerly the Bonitasoft community), including management of the creation or deletion of a community account.

As part of the Ofelia community, we also collect the content of your exchanges in order to process your requests and improve our products and services.

The retention period for data used in connection with the above processing operations is three years after the last contact between the Community member and Ofelia.

Processing based on the User's consent

  • Management of virtual and in-person events;
  • Management of written client testimonials (for as long as the author of the testimonial remains a client);
  • Management of contact requests;
  • Management of the newsletter;
  • Management of downloads.

Processing based on Ofelia's legitimate interest

  • Management and canvassing of prospects.

The retention period for data used in connection with the above processing operations (consent and legitimate interest) is three years after the last contact between the User and Ofelia, unless consent is withdrawn or an objection request is made.

What data does Ofelia collect and process?

In connection with the processing operations carried out by Ofelia, we may process the following data:

  • Your professional contact details (last name, first names, job title, email / telephone / employer's name / address);
  • The exchanges we may have with you (in connection with a contact or support request, or in connection with the performance of the contract);
  • Data related to your User account (including IP address and connection data);
  • Any questions or comments you send to us or post on our community, as well as the responses we provide to them.

Processing carried out by Ofelia as a data processor on behalf of its clients

Where the contract entered into with a User provides that Ofelia carries out the processing of personal data on its behalf, we act as a data processor within the meaning of Article 4 of the GDPR.

Processing carried out as a data processor concerns:

  • Management of Users' support requests (support);
  • Provision of Bonita Cloud services;
  • Security management on behalf of the client.

As part of the Ofelia Agentic offering, the following processing operations as a data processor may also be provided:

  • Assignment of connection authorizations (identity management, user access and account creation);
  • Ingestion and indexing of the knowledge base (RAG);
  • Database hosting;
  • Hosting of data related to prompts submitted by users;
  • Analysis of prompts and formulation of responses;
  • Execution of actions in third-party tools;
  • Configuration and execution of business processes.

The legal basis for these processing operations is defined by the User client, acting as data controller.

The User client also defines the personal data whose processing it entrusts to Ofelia.

In connection with the processing operations carried out as a processor, the personal data processed generally consist of:

  • data hosted by Ofelia for the Client or imported by the Client;
  • the Users' contact details and their connection authorizations;
  • connection data;
  • the textual content of prompts and responses.

Unless otherwise instructed by the client, data are retained for the term of the contract entered into with the client.

By way of exception:

  • data related to prompts submitted by Users are retained only for a rolling period of twelve months;
  • data related to the analysis of prompts and the responses formulated are retained for a rolling period of thirty days;
  • data related to the execution of actions in third-party tools are also retained for a rolling period of thirty days.

Once these periods have elapsed, personal data that may constitute necessary evidence in the event of litigation, and data subject to a legal or contractual retention obligation, are retained for the period provided for by law or by the contract. They are stored on a separate server, with restricted access, and used exclusively in connection with a claim or at the request of judicial or administrative authorities.

Who may have access to your personal data?

Only Ofelia personnel who strictly need to access your data in order to carry out one of the processing operations described in this Policy may be granted access to your data.

Ofelia never sells your data.

Where applicable, your data may be communicated to one of our processors, exclusively within the scope of and for the purposes of the performance of the subcontracted processing.

In such cases, the processor is bound by the same obligations regarding confidentiality and the protection of personal data as Ofelia.

Use of sub-processors

Ofelia reserves the right to engage sub-processors in order to provide the services accessible through the Solutions.

The list of Ofelia's current sub-processors may be communicated to the User at any time upon simple request.

Ofelia undertakes to engage only sub-processors that comply with the provisions of the GDPR.

Ofelia vouches for its sub-processors' compliance with the commitments it undertakes itself, in particular with regard to commitments it may make under standard contractual clauses or any other appropriate safeguard.

Transfer of personal data outside the European Union

Ofelia does not voluntarily transfer personal data outside the European Union.

In the event that a User or one of its processors is located outside the European Union or a country benefiting from an adequacy decision, Ofelia will implement all necessary legal measures to govern the data transfer. These measures shall take the form of either standard contractual clauses, adherence to the Data Privacy Framework, or another mechanism provided for by the GDPR.

Should the validity of the transfer instrument be called into question, Ofelia undertakes to immediately cease the transfer until the legal conditions required to authorize the transfer are once again met.

Security and confidentiality of personal data

Ofelia undertakes to implement all sufficient and appropriate technical measures to preserve the integrity and confidentiality of personal data and to protect it against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, as well as against any other form of unlawful processing. These measures must ensure, taking into account the state of the art and the costs of their implementation, a level of security appropriate to the risks presented by the processing and the nature of the personal data to be protected. Ofelia uses secure means of communication to process personal data.

Users' rights

Each User has the right to access, modify, rectify, object to and erase personal data concerning them.

The rights set out in the preceding paragraph may be exercised by contacting customer service at the following email address: gdpr@ofelia.com.

For any questions relating to the use of our Solutions, please refer to their respective terms of use.

Where a User's data are processed by Ofelia as a processor acting on behalf of a client data controller, requests to exercise data subject rights must be addressed directly to the data controller.

Ofelia has also appointed a Data Protection Officer: the company Virtual-DPO. It can be contacted at any time at contact@virtual-dpo.fr or via its website www.virtual-dpo.fr.

In the event of any difficulty relating to the management of their personal data, the User has the right to lodge a complaint with the CNIL (the French data protection authority) or with any competent supervisory authority.

This policy may be revised at any time.

If the User does not agree with the new version of our Data Protection Policy, they must stop using our Solutions after the effective date of the change.

External links

Links to other websites operated by third parties may be accessible from our Solutions. Even where the third party is affiliated with Ofelia through a partnership or any other contractual relationship, Ofelia cannot be held responsible for the practices implemented by that third party with regard to privacy or personal data, or for the content accessible from those sites. These links are provided solely to facilitate navigation on our interfaces, and you access them at your own risk.

Cookies

The website https://www.ofelia.com/fr may use cookies.

Some cookies are strictly necessary for the operation of our site.

Where Ofelia uses cookies that are not strictly essential to the operation of the site, they are only placed on the browser after acceptance by the site visitor. Browsing preferences can be changed at any time via the cookie management platform, accessible at any time from our home page.