Skip to content Skip to footer

Personal Data Protection

Personal Data Protection Statement

The data controller attaches particular importance to the protection of your personal data. Its processing is carried out exclusively in accordance with applicable regulations, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“GDPR”) and French Law No. 78-17 of 6 January 1978 on Information Technology, Data Files and Civil Liberties, as amended (“French Data Protection Act”).

1. Data Controller

The data controller of your personal data is ALPHA Europe Holdings S.A.S. (hereinafter the “data controller”).

Contact Information: Kiyomi Ichiro ichiro.kiyomi@kk-alpha.com

If you have any doubts or questions regarding the processing of your personal data, for any requests or complaints, or if you believe your data is being processed unlawfully or unfairly, or to exercise any of your rights, you can contact us at any time by email at the addresses mentioned above or by mail to the data controller’s address.

2. Purposes, Legal Basis, and Retention Periods

The data controller processes the personal data of data subjects to meet the legal, organizational, and operational needs of the company. Personal data is processed in a targeted manner for the following purposes:

Purpose of processing personal data Legal basis (Art. 6 § 1 GDPR) Shelf life

Contact form

(Handling requests, questions or inquiries)

Legitimate interest (point f) — interest in ensuring communication and providing assistance. For the time necessary to process the request (generally, a maximum of 1 year from the end of the exchanges).

Website operation and optimization

(statistical and analytical cookies)

Consent (point a) — collected by means of the cookie banner. Depending on the validity period of the cookie in question (specified in the cookie policy).

Video surveillance system (CCTV)

(Prevention of unauthorized access, protection of property and people)

Legitimate interest (point f) — protection of property and the safety of persons. A maximum of 1 month (CNIL recommendation). If an investigation into a security incident is required, the relevant extract will be kept for the period strictly necessary for that investigation.

Visitor Log

(Management and control of external access)

Legitimate interest (point f) — security of premises. Generally, 1 year from the end of the calendar year in which the visit was recorded.

Recruitment and selection procedures

(Application review)

CV retention

Pre-contractual relationships (point b) — at the request of the data subject.

Retention of CVs after the closure of the selection procedure, or processing of unsolicited applications, exclusively on the basis of consent (Art. 6 § 1 point a GDPR).

Data will be retained until the selection process is complete (maximum 2 years from the last contact, unless the candidate requests otherwise).

For longer retention (candidate pool), consent is required until the data is removed.

Personnel and payroll management

(Administrative management of employees)

Legal obligation (point c) and Performance of the contract (point b). In accordance with the specific provisions applicable (for example: payslips 5 years, or 50 years / until the legal retirement age plus 6 years for the electronic version — art. L. 3243-4 and D. 3243-8 of the Labour Code; employment contracts: 5 years after the end of the contract).

Business relations and contract management

(Relationship management, communication, contract execution)

Performance of the contract (point b) — natural person co-contractor, or Legitimate interest (point f) — contact persons of the B2B partners. For the duration of the contractual relationship.

Billing and accounting

(Compliance with financial obligations)

Legal obligation (point c) — Commercial Code, General Tax Code. 10 years following the calendar year to which the documents relate (art. L. 123-22 of the Commercial Code).

Litigation and debt collection

(Debt collection, defense of rights)

Legitimate interest (point f) — establishment, exercise or defence of legal rights. For the duration of the applicable limitation periods (generally 5 years, art. 2224 of the Civil Code), or for the duration of the dispute.

Whistleblowing (Receiving and processing reports, protecting whistleblowers)

(Receiving and processing reports, protecting whistleblowers)

Legal obligation (point c) — Law No. 2022-401 of March 21, 2022 aimed at improving the protection of whistleblowers and its implementing decree No. 2022-1284. For the duration necessary for the checks and until the case is closed; beyond that, only in a form that makes the persons unidentifiable (except in the case of ongoing legal proceedings).

Cybersecurity

(Ensuring the integrity and availability of systems, preventing incidents)

Legitimate interest (point f) — security of IT infrastructure and data. Depending on the type of security log concerned (generally 6 to 12 months).

Production data

(Monitoring of operator activity at production stations)

Legitimate interest (point f) — to ensure the operator’s responsibility for the work performed in the event of a customer complaint. Depending on the duration of the markets, operator information is anonymized in the event of departure or end of contract.

3. Categories of recipients

Personal data may be communicated to external accountants, health, safety and occupational medicine providers, legal advisors, public bodies (including URSSAF, the Health Insurance (CPAM) and the Directorate General of Public Finances (DGFiP)), as well as IT and cloud hosting service providers, acting as subcontractors within the meaning of Article 28 of the GDPR.

4. Data Subject Rights

As a data subject, you have the following rights regarding the processing of your personal data, in accordance with the GDPR and the French Data Protection Act:

  • Right of access to personal data — the right to obtain from the data controller confirmation as to whether or not personal data concerning you is being processed, and access to that data.
  • Right to rectification — the right to obtain the rectification (or completion) of inaccurate personal data.
  • Right to erasure — the right to obtain the erasure of personal data under certain conditions.
  • Right to restriction of processing — the right to obtain restriction of the processing of your data.
  • Right to object — the right to object to the processing of your personal data.
  • Right to data portability — the right to receive your data in a structured, commonly used, and machine-readable format.
  • Right not to be subject to an automated individual decision, including profiling. Right to withdraw your consent to the processing of your personal data (where the processing is based on consent), at any time and without affecting the lawfulness of the processing based on consent before its withdrawal.

Exercising your rights

If you wish to exercise any of your rights, you can use our request form, available upon request. If you are not satisfied with our response, if you believe your rights have not been respected, or that your personal data is being processed unfairly or unlawfully, you have the option of filing a complaint with the competent supervisory authority, namely the CNIL (Commission Nationale de l’Informatique et des Libertés), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.

5. Cookies (fichiers témoins)

Cookies are small text files that are stored on your device (computer, tablet, smartphone) when you visit our website. These files allow the website to recognize your device and remember certain information about your visit.

The data controller manages cookies in accordance with Regulation (EU) 2016/679 (GDPR), French Law No. 78-17 of 6 January 1978 on Information Technology, Data Files and Civil Liberties, the French Postal and Electronic Communications Code, and the recommendations of the CNIL (French Data Protection Authority) regarding cookies and other tracking technologies.

The use of analytical, functional, and marketing cookies is subject to the user’s consent, obtained through the CookieYes tool.

We use or may use the following categories of cookies:

Strictly Necessary Cookies

These cookies are essential for the proper functioning of the website. Without them, the website’s core functions could not be guaranteed.

The data processed may include: IP address (to a reasonably limited extent), device type, operating system, web browser type, language, session settings, and technical identifiers necessary for the website to function correctly.

Functional cookies

These cookies allow us to remember user preferences and provide enhanced functionality. They can be used, for example, with the following services: YouTube, Google Maps, login via third-party services, or other additional website features. These cookies are only activated after obtaining the corresponding consent.

Analytical (Statistical) Cookies

Analytical cookies allow us to collect anonymized statistical data on website usage in order to improve its content, functionality, and user experience. This website uses Google Analytics 4 (GA4). The data processed may include: anonymized IP address, approximate geographic location, device type, operating system, browser type, language, number of visits, pages viewed, visit duration, referral source, and other aggregated statistical data.

Cookies marketing

Les cookies marketing permettent l’affichage de publicités pertinentes et la mesure de l’efficacité des campagnes marketing. Le responsable du traitement n’utilise pas nécessairement de cookies marketing à ce jour. En cas de For future deployments (e.g. Meta Pixel, Google Ads, Google Tag Manager or similar services), these will only be activated after obtaining the visitor’s consent using the CookieYes tool.

Identification of data subjects

Data subjects are visitors to the website of the data controller.

Recipients of Personal Data

The data controller may communicate personal data to: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google Analytics 4); the website host, to the extent necessary for the operation of the website; the service provider CookieYes Limited, which manages cookie consent; and other subcontractors whose use is necessary for the operation of the website and who process data in accordance with Article 28 of the GDPR.

Data source

Personal data is collected directly from the website visitor, via their cookie settings entered in the CookieYes tool.

Data Retention Period

Each category of cookies is stored for a different duration depending on its type.

Analytical cookies are stored for a maximum of 13 months.

Strictly necessary cookies are only stored for the period strictly necessary for the proper functioning of the website

Cookie Management

Users can give or withdraw their consent via the CookieYes cookie banner or the “Cookie Settings” link available on the website. Users can also delete or block cookies directly from their web browser.

Information specific to each browser: Mozilla Firefox, Google Chrome, Microsoft Edge, Safari, Opera. Disabling certain cookies may result in some website features not being available.

6. Security of personal data

The data controller has implemented appropriate technical and organizational measures to protect personal data against:

  • accidental or unlawful destruction;
  • loss, alteration, unauthorized disclosure or access;
  • any other form of unlawful processing.

Only authorized personnel, bound by a duty of confidentiality, have access to personal data.

7. Retention Period for Personal Data

Personal data is retained only for as long as necessary to fulfill the purpose for which it was collected, or for the period stipulated by applicable regulations. Upon expiry of this period, personal data is securely deleted or anonymized.

8. Transfer of personal data to third countries

Some services (including Google Analytics 4 and other Google group services) may involve the transfer of personal data outside the European Economic Area, particularly to the United States of America. Such transfers are carried out only in compliance with the conditions set out in the GDPR and on the basis of appropriate safeguards, including an adequacy decision by the European Commission or standard contractual clauses