The KLEPIERRE Group, including each company that composes it (hereinafter the “KLEPIERRE Group” or “KLEPIERRE”), attaches great importance to protecting the privacy and data of users of its websites and mobile applications. These are comprised of the websites and mobile applications attached to shopping centers operated by KLEPIERRE. KLEPIERRE strives to adopt and comply with a strict confidentiality policy in accordance with the regulations in force.
KLEPIERRE is subject to the applicable rules on the protection of personal data and, in particular, the European General Regulation on the Protection of Personal Data no. 2016/679 of 27 April 2016 (known as the “GDPR”), as well as all the rules of national law adopted in application thereof, on a subsidiary basis.
The purpose of this Personal Data Protection Charter (the “Charter”) is to provide clear, simple and complete information to all persons concerned (“You” or “Your”) on the way in which KLEPIERRE, in its capacity as data controller, collects and uses personal data concerning You (“Personal Data”) and on the means at Your disposal to control this use and exercise Your rights relating thereto.
Table of contents
1. When are Your Personal Data collected?. 2
2. On what legal basis is Your Data processed?. 5
3. For what purposes are Your Personal Data collected?. 5
4. Who are the recipients Your Personal Data?. 6
5. How is the security of Your Personal Data preserved?. 10
6. How long are Your Personal Data stored?. 10
7. What are Your rights with regard to Your Personal Data and how can You exercise them?. 11
9. Governing law and jurisdiction. 13
(i) KLEPIERRE may collect Your Personal Data as part of Your visit and Your use of its online services or those of its partners, Your customer journey for these services (e.g. audience measurement cookies), or Your exchanges with the KLEPIERRE teams, in particular when
- creating a user account or candidate space,
- subscribing to a newsletter or any other alert system,
- signing up to a competition or loyalty program,
- responding to satisfaction surveys, or
- requesting contact with a KLEPIERRE contact person.
Your Personal Data may also be collected in connection with Your use of any other products and services offered by KLEPIERRE, particularly in its shopping centers.
Such Personal Data are those that You provide by means of forms, whether dematerialised or in paper format, whether on the websites or mobile applications made available by KLEPIERRE or in the terminals installed in its shopping centers, or in response to questions put to You by KLEPIERRE employees or service providers authorized by the latter.
On these occasions, KLEPIERRE takes into account the principles of data minimisation and protection, from the design stage of projects and by default (privacy by design and privacy by default). Consequently, only relevant, appropriate and limited information is collected for the purposes for which it is processed.
The Personal Data required for processing are indicated as mandatory in the input fields on the collection medium. Apart from these cases, You are free to provide all or part of Your Personal Data or not, bearing in mind that such a decision could have the consequence of limiting Your access to certain services or products offered by KLEPIERRE, or other functionality offered on its websites and mobile applications (e.g. collection of Your date of birth in order to wish You a happy birthday).
(ii) Social plug-ins
Our websites may use plugins (the " Plugins") provided by social networks (facebook.com, Instagram, etc.). The Plugins are identifiable by the social network logo to which they belong. They allow You to mark the pages of these networks in Your Favorites and share Your Favorites with their other users.
When You visit a page containing Plugins, Your browser connects directly to the corresponding social media servers. The Integrated Plugins indicate to the social network that You have accessed the corresponding page on our sites. If You are connected to the social network, Your visit may be attached to your social network account. If You interact with the Plugins, for example by clicking on the “share” button on Facebook, the corresponding information is sent directly from Your browser to the Facebook social network and retained by it. Even if You are not connected to the social network, there is a possibility that the Plugins will transmit Your IP address to the social network.
These comments also apply to the use of the “JustAsk” functionality that allows You to communicate with KLEPIERRE via Facebook Messenger.
For more information on the purpose and scope of data processing by social media and Your rights in this regard, and to set up options to protect Your privacy, please refer to the privacy policy of each of these networks’ websites, including:
Facebook data policy: accessible here
Instagram data policy: accessible here
(iii) Registration, connection via Facebook
We also offer You the possibility of registering with our websites using the Facebook registration button or via the "Login" button. If You choose to create an account using Your Facebook social network account, and subject to Your prior consent, the social network in question will send Us the Personal Data that You have communicated to them (including Your first name, last name, gender and email address)
(iv) Cookies
When browsing our sites, cookies may be placed on Your device (computer, phone or tablet), subject to the preferences You have set and that You may change at any time.
A cookie is a small text file containing information relating to navigation on these websites, the main purpose of which is to improve how they are viewed and make it possible to provide personalized services.
On computers, cookies are managed by the Internet browser.
These cookies may be session cookies (in this case, the cookie will be automatically deleted when the browser is closed) or permanent (in this case, the cookie will remain stored on the device until its expiry date).
Here are the cookies used by our websites.
How to accept or refuse cookies?
When You first access the website, a dedicated window presents the different types of cookies and You have the possibility to accept or reject them, category by category, except for session cookies (see above) which are essential but not traceable.
Then, it is always possible to configure Your browser so that cookies are stored on the device or rejected, either systematically, or depending on their sender, or to be informed when a cookie is stored in the terminal, so that it can be accepted or refused.
However, the removal of all cookies used by the browser, including those used by other websites, may lead to the alteration or loss of certain settings or information.
The configuration of each browser is different. You are responsible for following the instructions of Your browser editor as follows (links available on the date this page was last updated):
– If You use Internet Firefox: here
– If You use Edge: here
– If You use Safari: here
– If You use Chrome: here [KC1]
To find out more about cookies and their implications please consult the “Your traces” section of the CNIL website 'French data protection authority' accessible here[KC2].
COOKIES USED ON THE WEBSITE
ASP.NET_SessionId
ASP.Net_SessionId is a cookie used to identify the status of the visitor's session via page requests on the server. This cookie is only valid for the duration of Your browser session.
.Net
Other
sxa_site
CMS session used to identify the status of the visitor's session via page requests on the server. This cookie is only valid for the duration of Your browser session.
Sitecore
Other
ARRAffinity
Affinity cookies are used to help people who need to stay with a certain instance of a web application or website in Azure. The reason for this is that we try to be "stateless", but we do not always succeed. This means that the user must remain on the particular instance he is using until he breaks the state and then things are recorded at that time.
Azure
Necessary
SC_ANALYTICS_GLOBAL_COOKIE
Cookies are used to collect information about how visitors use our site. Cookies collect information in an anonymous form including the number of visitors to the site, the site from which visitors came to ours and the pages they visited.
Sitecore
Other
utag_main
The cookie is set by Tealium. The cookie is used to track information about a user's visit. The cookie is used to store a unique identifier, the time stamp at the beginning of a user's visit, the pages visited and the number of visits to the website. The data helps to improve the website and provide a better user experience.
Tealium
Analytics
_ga
_gid
Google Analytics cookie used to track the user in his navigation
Google Analytics
Analytics
AMNET
Advertising performance measurement.
More information : https://info.evidon.com/pub_info/1454?v=1&nt=1&nw=true
Evidon
Publicitaire
Advertising performance measurement.
More information https://www.facebook.com/help/1075880512458213/?helpref=hc_fnav
Publicitaire
uuid2,
Anj
usersync
Advertising performance measurement.
More information:
https://www.appnexus.com/cookie-policy
AppNexus
Publicitaire
(v) Collection from third party partners
Your Personal Data may also have been sent to us by third party partners so that You can benefit from our newsletters, offers, discounts and other promotion. In particular, these are companies in charge of loyalty programs and retail shops present in KLEPIERRE shopping centers. As with all of our Personal Data processing, regardless of its source, we take into account there also the requirements of applicable regulations, in particular the principles of data minimisation and protection from the design stage and by default. Consequently, only relevant, appropriate and limited information is collected for the purposes for which it is processed.
Please note that in such cases, the confidentiality policies of the partners concerned, enabling them to transfer Your Personal Data to KLEPIERRE, could be applicable to You.
Your Personal Data is only processed by KLEPIERRE in the cases permitted by the applicable regulations, and in particular under the following conditions:
- when You have expressed free, specific, informed and unequivocal consent to the processing of Your Personal Data (e.g. subscription to a newsletter, partner offers, etc.);
- when necessary for the performance of a contract or pre-contractual measures taken at Your request (e.g. an application within the KLEPIERRE Group);
- compliance with the legal or regulatory obligations of the KLEPIERRE Group (e.g. combating fraud);
- when the legitimate interests of KLEPIERRE or the recipients may justify KLEPIERRE processing Your Personal Data (e.g. IT security measures) accompanied by adequate protection guarantees.
Clear information in accordance with applicable law is provided for in each case.
Your Personal Data are collected for specific, explicit and legitimate purposes.
Depending on the case, Your Personal Data may be used for the purpose of:
- Manage and provide You with the services of the Digital Platform;
- Allowing You to request and obtain information about the KLEPIERRE Group or one of its entities, a KLEPIERRE shopping center, or about the products and services offered by the latter or their partners;
- Administer Your subscription
- Allowing You to subscribe to and receive a newsletter or any other alert system;
- Allowing You to create and manage a user account on the website of a shopping centre operated by the KLEPIERRE Group in order to benefit from information, products and/or services or any other types of benefits offered by KLEPIERRE, a shopping centre or their partners;
- Responding to Your request to rent a permanent room or a temporary space within a shopping centre belonging to the KLEPIERRE Group;
- Participating in satisfaction surveys, analyses and statistics to improve our products and services as well as knowledge of our customers and prospects;
- Processing Your application for a position within the KLEPIERRE Group;
- Managing our loyalty programs;
- Improving Your customer experience and/or offering You tailored and personalised services.
- Analyze Your use of the Services and, subject to Your prior authorization, combine Your personal information collected when You use our various Services (i.e., loyalty card, mobile applications, websites, social networking accounts and promotional activities) to improve our understanding of Your expectations and needs, and develop new features and services
- Measure, test and monitor the indicators and effectiveness of our Services
- Ensure the technical functioning of the Services and protect Your personal information against theft, loss, damage or unauthorized access.
None of Your Personal Data is currently processed by us to make an automated decision about You, including profiling. However, KLEPIERRE will be able to send You personalised advertising and other specific offers based on Your own personal information and the analysis of Your user behaviour and, in particular, the consumption preferences that You have reported to us. You may oppose this profiling at any time under the conditions described in Article 7 below.
KLEPIERRE may also use Your Personal Data for administrative purposes or for any other purpose imposed by the legislation in force (for example, to notify You of a significant change made to this Charter).
As Your Personal Data is confidential, only persons duly authorised by KLEPIERRE due to their functions can access Your Personal Data, without prejudice to their possible transmission to the extent required by the applicable regulations.
All persons for which KLEPIERRE is responsible with access to Your Personal Data are bound by a confidentiality agreement and are exposed to disciplinary measures and/or other sanctions if they do not comply with this commitment.
These persons include authorised personnel within the KLEPIERRE Group, and more specifically, depending on the case, the purchasing, marketing, commercial, administrative and accounting, logistics and IT departments, the human resources departments, customer relations and their line managers.
Our authorised service providers may also be required to process Your Personal Data strictly necessary for the performance of the services we entrust to them: these include, in particular, service providers responsible for conducting satisfaction surveys, monitoring customer opinions, organising competitions, managing customer relations, managing loyalty programmes, sending e-mails for marketing data, and customer behaviour analysis. It is hereby specified that the management of our websites and mobile applications is currently carried out by the following service provider who processes Your Personal Data on our behalf as a subcontractor: PROXIMITY, a simplified limited company registered in the Nanterre Trade and Companies Register under number 382 163 087 and whose registered office is located at 52 avenue Emile Zola, 92 100 Boulogne Billancourt.
Subject to Your prior and express consent, Your Personal Data may also be transmitted to our Partners for marketing purposes and to benefit from their own newsletters, discounts, offers and other promotions. These "Partners" consist of permanent or temporary brands present in shopping centers operated by KLEPIERRE.
Your Personal Data may also be transmitted to PROXIMITY's subcontractors for the purposes described below:
TEALIUM:
SELLIGENT France SA:
vii. Duration of Processing/PD retention periods: The Customer, as well as the Data Controller, determines the period during which PD is hosted on the Selligent Platform. The PD of the Data Controller is not, under any circumstances, stored on the Selligent Platform after the termination of the contract between Selligent and its Client.
Microsoft:
Types of PD targeted: Contact information, including first name, surname, postal address, landline and mobile telephone number, and e-mail address, Information that a contact, client, or prospect of the Data Controller has completed in a form
Your Personal Data may also be forwarded in order to comply with legal or regulatory requests, court rulings, summons or legal proceedings, if required by the law in force.
Lastly, Your Personal Data may be transferred to a transferee in the event that the assets of KLEPIERRE are sold or transferred to a third-party company.
In the event of the use of service providers located outside the European Union, KLEPIERRE undertakes to check that appropriate measures have been put in place to ensure that Your Personal Data benefits from an adequate level of protection (in particular thanks to standard contractual clauses of the European Commission, internal company rules or the Data Protection Shield set up between the European Union and the United States).
Passman :
KLEPIERRE strives to protect and secure Your Personal Data, in order to ensure its confidentiality and to prevent it from being distorted, damaged, destroyed or disclosed to unauthorised third parties.
Where the disclosure of data to third parties is necessary and authorised, KLEPIERRE ensures that such third parties guarantee the same level of protection as that offered by KLEPIERRE, and requires contractual guarantees to ensure in particular that the data is solely processed for authorised purposes, with all the necessary confidentiality and security.
KLEPIERRE implements technical and organisational measures to ensure that the Personal Data is kept as securely as possible, for the period necessary for the exercise of the intended purposes, in accordance with applicable law.
Although KLEPIERRE takes all reasonable steps to protect Your Personal Data, no transmission or storage technology is totally infallible.
In accordance with the applicable European regulations, in the event of a proven breach of Personal Data that could create a high risk for the rights and freedoms of the persons concerned, KLEPIERRE undertakes to communicate the breach to the competent supervisory authority and, where required by said regulations, to the persons concerned (individually or generally, depending on the case).
Without prejudice to the above, You must exercise caution to prevent unauthorized access to Your Personal Data and Your devices (computer, smartphone, tablet, etc.), in particular by choosing a robust password.
Furthermore, the KLEPIERRE Group's websites and mobile applications may offer links to websites of third parties that may interest you (e.g. social networks). KLEPIERRE has no control over the content of these third-party websites or the practices of these third parties with regard to the protection of the Personal Data that they may collect. Accordingly, KLEPIERRE accepts no liability for the processing by these third parties of Your Personal Data, which is not subject to this Charter. It is Your responsibility to obtain information on the personal data protection policies of these third parties.
KLEPIERRE retains Your Personal Data only for the time needed to achieve the intended purposes, subject to the legal possibilities of archiving, the obligation to retain certain data and/or anonymisation.
In particular, we apply the following retention periods for the following broad categories of Personal Data:
• Personal Data from the subscribers to the digital platform: retained as long as the user remains active and, at the latest, 3 years after the last contact with the user;
• Personal connection data: 1 year maximum from the connection;
• Cookies: 13 months maximum from insertion into the browser;
• Personal Data of job applicants (recruitment section): the time required to process the application and, in the event of a negative outcome, a maximum of 2 years after the last contact (unless the candidate agrees for a longer period).
(i) Your Rights
Subject to the limits provided for by the regulations in force, You have the following rights with regard to Your Personal Data:
➢ Right to be informed about the processing of Your Personal Data
KLEPIERRE strives to provide You with concise, transparent, comprehensible and easily accessible information, in clear and simple terms, on the conditions under which Your Personal Data is processed.
➢ Right of access, rectification and erasure (or "right to be forgotten") with regard to Your Personal Data
The right of access allows You to obtain from KLEPIERRE confirmation that Your Personal Data is processed by us or not, and the conditions of this processing, as well as to receive a copy thereof (for any additional copy, KLEPIERRE is entitled to require payment for reasonable expenses based on the administrative costs incurred). When this request is submitted electronically, the information is provided in customary electronic format, unless You request otherwise.
You also have the right to obtain from KLEPIERRE the prompt rectification of Personal Data which is inaccurate or incomplete.
Finally, subject to the exceptions provided for by applicable law (e.g. retention necessary to comply with a legal obligation), You have the right to ask KLEPIERRE to erase Your Personal Data promptly for one of the following reasons:
- Your Personal Data is no longer necessary for the purposes for which it was collected or otherwise processed;
- You wish to withdraw Your consent on which the processing of Your Personal Data was based, where applicable, and there is no other basis for such processing;
- You consider and can establish that Your Personal Data has been unlawfully processed;
- Your Personal Data must be erased by virtue of a legal obligation.
➢ Right to restrict the processing of Your Personal Data
The applicable regulations provide that this right may be asserted in certain cases, including the following in particular:
- when You dispute the accuracy of Your Personal Data, for the time required to verify its accuracy;
- when You consider and can establish that the processing of Personal Data is unlawful but You oppose the erasure of the Personal Data and instead require that the processing be limited;
- when KLEPIERRE no longer needs Your Personal Data but You still need them to establish, exercise or defend Your legal rights;
- When You object to the processing based on the legitimate interest of the data controller, for the time required to verify whether the legitimate interests pursued by the data controller prevail over yours.
➢ Right to object to marketing (including profiling)
You may object at any time to the processing of Your Personal Data for marketing purposes. You may also object to profiling only. In this case, You will no longer receive personalized offers.
➢ Rights to the portability of Your Personal Data
Where the processing is based on Your consent or a contract, the right to data portability allows You to receive the Personal Data that You have provided to KLEPIERRE in a structured, commonly used and machine-readable format, and to transmit this Personal Data to another data controller without KLEPIERRE creating any obstacles thereto.
Where technically possible, You may request that this Personal Data be sent directly to another data controller by KLEPIERRE.
➢ Right to withdraw consent to the processing of Personal Data
When KLEPIERRE processes Your Personal Data on the basis of Your consent, it may be withdrawn at any time using the means made available to You for this purpose (hyperlink and/or procedure indicated in point 7.2 of this Charter). However, and in accordance with applicable law, the withdrawal of Your consent is only valid for the future and cannot therefore call into question the legality of the processing carried out before this withdrawal.
➢ Right to lodge a complaint with a supervisory authority
If, despite KLEPIERRE’s efforts to preserve the confidentiality of Your Personal Data, You believe that Your rights are not respected, You are entitled to lodge a complaint with a supervisory authority.
A list of the supervisory authorities is available on the European Commission's website.
➢ Right to decide the fate of Your Personal Data after your death
Finally, You have the right to organize the fate of Your post-mortem Personal Data by adopting general or specific directives. KLEPIERRE undertakes to comply with these directives.
In the absence of directives, KLEPIERRE recognises the rights of heirs to exercise certain rights, in particular the right of access, if necessary for the settlement of the estate of the deceased; and the right of opposition to close the deceased's user accounts and oppose the processing of his/her data.
(ii) Procedures for exercising Your rights
For any questions relating to this Charter and/or to exercise Your rights as described above, You can change your information at any time via the "My Account" page or for a specific question (not covered by the options offered on the "My account" page) You can contact KLEPIERRE, by email or post, by sending a letter accompanied by a copy of any identity document to: dpo@klepierre.com
KLEPIERRE undertakes to reply to You as soon as possible and in any event within one month of receipt of Your request.
If necessary, this period may be extended by two months, given the complexity and number of requests addressed to KLEPIERRE. In this case, You will be informed of this extension and the reasons for the postponement.
If Your application is submitted in electronic form, the information will also be provided to You electronically wherever possible, unless You expressly request otherwise.
If KLEPIERRE does not respond to Your request, it will inform You of the reasons for its inaction and You will have the possibility of submitting a complaint to a supervisory authority and/or bringing legal proceedings.
Operating Authorisation
With a view to promoting the shopping centres it operates, Klépierre ("Klépierre") intends to use one or more of your photograph(s) posted on your Instagram page ("Photograph(s)" and "You"/"Your").
Klépierre contacted you by commenting on the Photograph(s) on your Instagram account.
The purpose of this authorisation is to define the conditions under which you authorise Klépierre to use the Photograph(s).
(i) Distribution media
You authorise any reproduction and/or representation and/or distribution, with no limits on quantity, of the Photograph(s) by Klépierre on the following media:
- On any website belonging to and operated by Klépierre or any company belonging to the Klépierre Group,
- On the digital screens ("social walls") of shopping centres operated by Klépierre or any company belonging to the Klépierre Group,
- In newsletters sent by Klépierre or any company forming part of the Klépierre Group to promote its shopping centres.
This authorisation also includes any reproduction and/or representation and/or dissemination of your image that may be reproduced on the Photograph(s).
(ii) Duration of use
This authorisation is granted worldwide and for a period of 18 months from the first use.
The Photograph(s) may be used by any company that is part of the Klépierre Group.
(iii) Third-party rights
You guarantee Klépierre that the Photograph(s) does/do not contain any item likely to infringe the rights of a third party, and in particular intellectual property or image rights, and guarantee Klépierre against any recourse or action that may be taken for whatever reason by any natural or legal person who considers that it/he/she must assert any rights over the Photograph(s).
You acknowledge that you have read these terms and conditions before giving Klépierre authorisation to use the Photograph(s).
This authorisation will be formalised by a comment by you "Yes followed by the name of the shopping centre", or any other equivalent phrase, posted in response to Klépierre's comment on the Photograph(s).
(iv) Requesting the deletion of a photo
You may, at any time, request that the photo posted be deleted by sending your request to ks_marketingdigital@klepierre.com. This request must include:
- The Instagram/Facebook username
- The URL or screenshot of the photo to be deleted if several photos have been shared
Governing law and jurisdiction
This Charter is subject to French law. In the event of a dispute and in the event that an amicable agreement cannot be reached, the competent court shall be that determined in accordance with the applicable rules of procedure.