en
fr

Privacy Policy

Last updated: September 2026

1. Purpose and Scope

DataOne (“DataOne”, “we”, “us” or “our”) is committed to protecting your privacy and personal data.
This Privacy Policy (“Policy”) explains how DataOne collects, uses, stores, shares and protects personal data when you visit www.dataone.eu (the “Website”) or otherwise interact with us through the Website or our related online services.

This Policy applies, as relevant, to Website visitors, customers and prospective customers, suppliers and business partners, job applicants, and other individuals who interact with DataOne through the Website.

For the purposes of personal data collected and processed through the Website, the data controller is DataOne France SAS, 3 rue Chauveau-Lagarde 75008, Paris, France (“DataOne”), together with its affiliates where applicable to the relevant processing activities.

This Policy should be read together with our Cookie Policy, which explains how we use cookies and similar technologies.

2. Data Protection Principles

DataOne processes personal data in accordance with applicable data protection laws and the following principles:

a. Lawfulness, Fairness and Transparency: personal data shall be processed lawfully, fairly and transparently;

b. Purpose Limitation: personal data shall be collected for specified, explicit and legitimate purposes and shall not be further processed in a manner incompatible with those purposes;

c. Data Minimisation: personal data shall be adequate, relevant and limited to what is necessary for the purposes for which it is processed;

d. Accuracy: personal data shall be accurate and, where necessary, kept up to date;

e. Storage Limitation: personal data shall not be retained for longer than necessary for the purposes for which it is processed; and

f. Integrity and Confidentiality: appropriate technical and organisational measures shall be implemented to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage.

3. Personal Data We Collect

We may collect and process the following categories of personal data:

Information you provide directly to us, including when you complete a contact form, request information, subscribe to a newsletter, submit a job application, or otherwise

communicate with us through the Website:

● identification and contact information, such as your name, email address, telephone number, company and job title;

● information contained in communications or enquiries submitted to us;

● where applicable, recruitment information, including your CV/résumé, employment history, qualifications and other information included in your application; and

● any other information you choose to provide to us.

Information collected automatically when you use the Website, which may include:

● IP address;

● browser type and version;

● device and operating-system information;

● Website usage and navigation information; and

● information collected through cookies and similar technologies.

We may also receive personal data from third parties where appropriate, including business partners, recruitment platforms, analytics providers and publicly available sources.

DataOne does not intentionally collect special categories of personal data through the Website unless such information is specifically required and an appropriate lawful basis

applies.

4. Cookies and tracking

We may process personal data for the following purposes and on the corresponding lawful bases, as applicable:

Purpose Legal basis
Responding to enquiries and providing requested information Legitimate interests and/or steps prior to entering into a contract
Managing relationships with customers, suppliers, business partners and other stakeholders Performance of a contract and/or legitimate interests
Processing and assessing job applications, where applicable Steps prior to entering into a contract and/or legitimate interests
Sending newsletters and marketing communications Consent, where required
Operating, securing, maintaining and improving the Website Legitimate interests
Website analytics and non-essential cookies Consent, where required
Complying with legal and regulatory requirements Compliance with legal obligations

Where we rely on legitimate interests, we consider those interests against the rights and interests of the individuals concerned.

Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.

In accordance with the GDPR, DataOne does not currently use personal data collected through the Website to make decisions based solely on automated processing, including profiling, that produce legal effects concerning individuals or similarly significantly affect them.

5. Cookies and Similar Technologies

The Website may use cookies and similar technologies to operate securely, remember preferences, understand Website usage and improve Website functionality and

performance.

Where consent is required under applicable law, non-essential cookies will only be activated after the user has provided the required consent.

Further information about the cookies used by DataOne and how users can manage their preferences is available in our Cookie Policy.

6. Disclosure and Sharing of Personal Data

DataOne does not sell personal data.

We may disclose or share personal data, where necessary and subject to appropriate safeguards, with:

● other companies within the DataOne and BSO group, where relevant to the purposes described in this Policy;

● service providers supporting our Website and business operations, including IT, hosting, analytics, communications and recruitment providers;

● professional advisers, including legal advisers, auditors and accountants;

● business partners, suppliers and subcontractors where necessary for the relevant business relationship or requested service;

● competent authorities, regulators, courts or other third parties where disclosure is required by applicable law or legal process; and

● a purchaser, successor or other relevant party in connection with an actual or proposed merger, acquisition, restructuring, financing or transfer of all or part of DataOne’s business or assets.

Where third parties process personal data on DataOne’s behalf, DataOne requires appropriate confidentiality, data protection and security obligations, as applicable.

7. International Transfers

DataOne operates internationally and may share or process personal data within the DataOne and BSO group or through service providers located in different jurisdictions.

Where personal data is transferred outside the European Economic Area (“EEA”), or otherwise to a jurisdiction that does not provide an equivalent level of protection, DataOne implements appropriate safeguards as required by applicable data protection laws. Such safeguards may include an adequacy decision, the European Commission’s Standard Contractual Clauses, or another legally recognised transfer mechanism.

You may contact us at contact.legal@dataone.eu to obtain further information regarding the applicable transfer mechanism and, where available, a copy of the relevant safeguards.

8. Data Storage and Security

DataOne implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Such measures may include access controls, secure hosting, encryption where appropriate, and restriction of access to authorised personnel.

While no transmission of information over the internet can be guaranteed to be completely secure, DataOne takes reasonable measures to protect personal data both during transmission and once received.

9. Data Retention

DataOne retains personal data only for as long as reasonably necessary for the purposes for which it was collected and processed, including to comply with applicable legal, regulatory, accounting or reporting requirements.

The applicable retention period will depend on the nature of the personal data, the purpose of processing, the relationship with the individual concerned and applicable legal requirements.

Where personal data is no longer required, it will be securely deleted, anonymised or otherwise handled in accordance with applicable law.

10. Your Rights

Subject to applicable data protection laws and any relevant limitations or exemptions, you may have the right to:

● request access to your personal data;

● request correction of inaccurate or incomplete personal data;

● request deletion of your personal data;

● request restriction of processing;

● object to certain processing, including processing based on legitimate interests and direct marketing;

● request portability of your personal data, where applicable;

● withdraw consent at any time where processing is based on consent; and

● lodge a complaint with the competent data protection supervisory authority.

Requests relating to the exercise of data protection rights may be submitted to: contact.legal@dataone.eu
DataOne will respond to requests within the timeframe required by applicable law.

11. Children's Privacy

The Website may contain links to third-party websites or services that are not operated or controlled by DataOne.

DataOne is not responsible for the privacy practices or content of such third-party websites. Users should review the applicable privacy policies before providing personal data to third parties.

12. Changes to this Privacy Policy

The Website is not directed at children, and DataOne does not knowingly collect personal data from children through the Website.

If DataOne becomes aware that personal data relating to a child has been collected without an appropriate lawful basis or required authorisation, DataOne will take appropriate steps in accordance with applicable law.

13. Changes to this Privacy Policy

DataOne may update this Privacy Policy from time to time to reflect changes in its practices or applicable legal, regulatory or operational requirements.

Any updated version will be published on this page with a revised “Last Updated” date.

14. Contact us

For questions, requests or concerns regarding this Privacy Policy or DataOne’s processing of personal data, please contact: contact.legal@dataone.eu