This text is a translation of the original in French. The English translation is offered for ease of understanding and is not a legally binding substitute for the original French version.
The original version is available at the following address: https://www.hakisa.com/fr/confidentialite
The General Data Protection Regulation (GDPR) requires to give explanations about the collected data and their use within the platform in order to obtain informed consent from the user.
Thus, we present to you a synthetic vision of data use for each of the features of the platform.
NB: some features are only accessible for administrator roles and/or by caretaker roles in alarm management.
The aim of the present document is to describe the conditions under which Hakisa (hereinafter "HAKISA" or “the provider”) collects and processes personal data (hereinafter "data") of its clients (hereinafter "user" or "you") when using the website (hereinafter "the Website" or “the platform”) under the conditions described in the "General terms and conditions of use".
HAKISA SAS is responsible for data processing.
HAKISA SAS 3 Rue Désiré Christian, 57960 Meisenthal, France Tél. : +33 (0)3 88 24 55 14
HAKISA is a simplified joint-stock company (Société par Actions Simplifiée, SAS) with a capital of 429 168 € registered under the number TI 538 224 254 of the RCS of SARREGUEMINES which intercommunity VAT number is FR07538224254.
3. GENERAL PRINCIPLES OF PERSONAL DATA MANAGEMENT ON THE HAKISA PLATFORM
The data are stored in Germany, a member of the European Community.
Most of the stored information is time-stamped to allow chronological display and/or debugging in case of technical issues.
Technical information (browser, operating system, IP address) is also stored for debugging and platform enhancement purposes.
Hakisa does not store any banking or medical data except those freely communicated in messages by the users themselves.
In accordance with the French legislation governing data storage conditions for Hakisa, deleted personal data is stored for a period of one year. These data are exclusively accessible on request from the justice to Hakisa. For the same reasons, the user's IP address at the time of connection is also stored.
Hakisa allows the effective deletion of accounts and anonymization of posted messages for the entire duration of use of the platform by the user.
Hakisa stores only the data required for:
The type of data collected and its use are detailed in the section "Use of data in the services available on the Hakisa platform" below.
The processing of these data has been declared at the French "National Commission on Informatics and Liberty" (Commission Nationale de l’Informatique et des Libertés - CNIL).
In accordance with the clauses of article 22 of the French Law n° 2004-575 of June 21st, 2004 considering the confidence of the online economy ("Loi pour la Confiance dans l'Economie" - LCEN), in agreement of the User, HAKISA is able to use the collected data to inform the user about the services.
Hakisa only shares your data with third parties in the following situations:
In order to improve the user experience, Hakisa uses login cookies.
A cookie is a text file sent to your browser from the visited website (here, the Hakisa platform). Information is stored using this cookie file, in particular, the language of your browser, your browsing habits or your login information (email address and password).
The Hakisa platform has a defined and targeted advertising space displayed to its users. The cookies used by Hakisa make it possible to offer targeted advertising to each user, according to the browsing habits recorded in those cookies.
For Microsoft Internet Explorer :
For Mozilla Firefox :
For Chrome :
Pour Safari :
The safety of its users' data is extremely important to Hakisa. Hakisa implements all appropriate measures to restrict data access to unauthorized third-parties.
Hakisa agrees to implement any measure to ensure the protection of the data in its possession in order to limit the risk of loss, theft, deterioration and any misuse of these data.
Access rights and rectification of data
In accordance with the clauses of the French Law n° 78-17 of January 6, 1978 related to informatics, files and liberty, the User benefits of the right to access, correct, modify and delete his personal Data.
To exercise these rights, please write to the following address:
The request will be fulfilled within the legal deadline of one month following the request.
4. USE OF DATA IN THE SERVICES AVAILABLE ON THE HAKISA PLATFORM
Hakisa collects two types of sensitive data in the user profile: mandatory data and optional data. This data is provided with the user's consent, at the time of registration on the Hakisa platform and / or when he changes his account information.
The mandatory sensitive data collected for all users are:
The optional sensitive data collected are:
The non-sensitive data collected:
When the user registers on the platform, he is asked to choose a password. The password of the user account is stored thanks to a hash function, i.e. it is stored encrypted, without any possibility of being decrypted. Thus, the user is the only owner of the password.
The user expressly agrees to maintain the confidentiality of his password.
The user accepts not to use the profile, username and password of another User, nor to disclose its password to a third party.
The user expressly agrees to inform Hakisa in case of suspicion of a non-authorized use of its profile or access to its password.
The user is the only responsible for the use if its profile.
Notifications & emails
Sending of notifications
The platform includes a real-time notification system. This system makes it possible to notify the user when events concerning him occur such as a new article in one of his Clubs, a new invitation to an event or a new contact request.
These notifications are sent on the Hakisa platform. They can also be relayed to an mobile application using the Progressive Web apps technology a smartphone and tablet application running on Android with the Chrome browser, upon installation and configuration of the application by the user.
The user can configure the notifications they wish to receive or not.
Sending of emails
Some notifications can also be sent by email, such as new messages in "My Contacts" or invitations. The user can configure his email preferences in his profile.
NB: when using the Alarms application, the email settings are different since they concern the sending of critical alarms via email (see dedicated section).
Some emails are mandatory and cannot be disabled, including :
The "My Contacts" section is the communication section between users. To add another user to his contacts, the user must know the user's email address.
It is not possible to find a person on Hakisa without knowing his email address.
However, Hakisa may suggest new contacts to a user in the case where the user has taken part in a group conversation containing at least one contact of the user and persons to whom he is not yet connected.
Thus, the data stored in "My Contacts" section are:
"My Photos" allows the user to create photo albums. Users can share their photo albums with their contacts. In the case of photo album sharing, people participating in the photo album can: view photos, download them on their computer, comment them, delete them and add photos to the album.
It should be noted that users participating in a photo album may also invite other users who are part of their contacts.
In this context, the following data are stored:
"My Internet" allows the user to access websites sorted into categories in order to simplify their access.
Users can create their own categories and buttons (link to websites) and customize them.
The stored data concerning the "My Internet" buttons are:
In this section, the user can create timestamped events in his agenda and invite people to his events.
People accepting invitations are personally associated with the event and their avatar appears in the area provided.
It is also possible to join a community event (a Club) and in this case, the facilitator who created the event is notified of the member's participation.
In this section, the user can play various online games.
No sensitive personal data is collected.
At any time and from any page of the platform, the user can send a feedback to the administrators of the platform in case of a technical problem encountered or to ask them a question about the use of the platform features.
In order to best respond to the user's request, we collect technical information about the customer's environment: the operating system (OS) and web browser used.
To allow debugging, the remarks sent are nominative and timestamped and are visible only by the administrators of the platform.
My Clubs (users)
In this section, the user will be able to access the content and services of the communities (Clubs) of which he is a member. There are open communities, which can be joined without invitation (Sponsored Clubs, Restricted Clubs) and closed communities, which can only be joined by invitation from administrators (Exclusive Clubs).
Data shared within the Club
Within Clubs, there are two types of content:
The user member of a Club can react to the internal content of the Club by posting 3 types of messages:
NB: when a user deletes his account, messages posted within Clubs are anonymized.
Within an Exclusive Club, the administrator can activate a member directory feature. In this case, the obligatory personal data of the Club user are visible by the other members (name, first name, email address, postal code, city, country). In case they are filled out by the user, the optional personal data are also visible by the other members of the Club (postal address, landline, and mobile phone numbers).
At any time the user can:
Data shared with community (Clubs) administrators
By joining a community (a Club), the user agrees to share data with the Club administrators, namely:
Messages posted within the Club
The messages posted by a user within a Club are nominative and timestamped. The Club administrator has access to the message data and the user who posted it: name, first name, date and time of the message, message content, user's email address (in the case of an Exclusive Club only).
Club events can be defined by the administrators who may or may not send invitations to members. The administrator has access to the list of users participating or not in the event with, for each user: his last name, first name and the status of his invitation (participates, pending, does not participate).
This feature allows the administrator to create directories and upload files accessible to all Club members.
No user data is stored on document sharing and usage.
Conversations with administrators
This feature allows the user of a Club to start a private conversation with a Club manager. The conversation is always initiated by the user and is visible only by the Club manager.
The manager then has access to the following user's personal data: the user's first and last name, email address, the content of the messages and the date the messages were sent.
The conversation also has a processing status, updated by the administrator and visible to the user.
This feature allows a Club manager to offer surveys to Club members. There are two types of surveys:
External services (hosted outside the platform) are optional within the Clubs.
In this case of use, all data is managed by the third party platform responsible for the service in question, and not by Hakisa.
As such, the collection and use of this data must, therefore, be made explicit to the user of the said service.
The platform has an online support system. A user can become another user's "digital sponsor" or ask one of his contacts to become his digital sponsor. In order to request help or become a digital sponsor, the user must :
By accepting this link of digital mutual aid, the sponsored agrees to share with his digital sponsor the following data:
At any time, the sponsor or the sponsored person can delete this digital mutual aid relationship. Thus, the digital sponsor no longer has access to the data detailed above.
If desired, the user can install the notification application on his mobile device (available on Android starting release 4.4 and Chrome with the latest release installed) to receive the platform's push notifications on his device.
The mobile application does not request access to the user's personal data on his device.
This section only applies to users who have access to the administration interface. In this case, the user assumes an administrator role.
A role hierarchy defines access to the various administrative functions:
In order to allow the animation and administration of the platform, as well as the technical support and possible debugging, Hakisa stores data regarding the contents created in the Back-Office:
By accepting an administration role on the platform, the administrator agrees to share additional data about the content he creates on the platform with Hakisa.
This section only applies to users who have subscribed to the alarm management application as an owner or caretaker.
Subscription to the alarm application
Subscription to the alarm application, as owner or caregiver, implies the consent sharing of the following personal data (to the caregiver circle and to the system operator):
The platform allows the collection and distribution of alarms from sensors and IoT systems connected to external platforms. The interconnection of these platforms allows the identification of an alert system and its association with a user account.
Alarms are emitted by the alert system and are shared:
For each alarm, the previously mentioned entities have access to :
5. POLICY REGARDING DATA PROTECTION
Hakisa reserves the right to edit at any time its policy regarding data protection and to apply all potential modifications to all owned data concerning the user.
The operator commits to inform the user in the event of major changes to its data processing policy.
The user is therefore advised to regularly consult the present document in order to be perfectly aware of any potential modification made by Hakisa.