Data Privacy Notice
For Technical Support, Product Information, Security Reports and Product or Service Complaints
General Information
For general information regarding the processing of Personal Data by Osborne Systems inconnection with its Website, please refer to the Osborne Systems Privacy Policy.
At Osborne Systems SAS (“Osborne Systems”, “we”, “us” or “our”), we take data privacyseriously and process Personal Data in accordance with applicable privacy and data protection laws, including the European Union General Data Protection Regulation (“GDPR”) and applicable French data protection legislation.
Email: info@osborne-systems.com
Osborne Systems develops software and technology solutions for industrial engineeringapplications.
OSBORNE SYSTEMS SAS
100 Avenue des Ternes
75017 Paris
France
This Privacy Notice explains how Osborne Systems collects and processes Personal Datain connection with:
Any request concerning this Privacy Notice or the exercise of data protection rights maybe sent to:
- technical support requests;
- product or service information requests;
- software issues and incident reports;
- cybersecurity or vulnerability reports;
- feedback relating to Osborne Systems' technologies, products or services; and
- product or service complaints.
Contact Details
The scope of this Notice is limited to Personal Data processed for these purposes.
In France, the competent supervisory authority is the Commission Nationale de l'Informatique et des Libertés (CNIL).
For general information about how Osborne Systems processes Personal Data in connectionwith its public Website, please refer to the Osborne Systems Privacy Policy.
You also have the right to lodge a complaint with the competent data protection supervisoryauthority.
The data controller is:
Certain rights may be limited where Osborne Systems has a legal obligation or legitimatelegal ground to retain or continue processing particular information.
OSBORNE SYSTEMS SAS
100 Avenue des Ternes
75017 Paris
France
- the right to obtain information about the processing of their Personal Data;
- the right to access their Personal Data;
- the right to request correction of inaccurate or incomplete Personal Data;
- the right to request deletion of Personal Data in certain circumstances;
- the right to request restriction of processing in certain circumstances;
- the right to receive certain Personal Data in a structured, commonly used and machine-readable format where the right to data portability applies;
- the right to object to processing based on Osborne Systems' legitimate interests; and
- where processing is based on consent, the right to withdraw consent at any time.
RCS: 989 862 552
Subject to the conditions and limitations provided by applicable data protection legislation,individuals may have the following rights concerning their Personal Data:
Email: info@osborne-systems.com
Information Regarding Your Rights
Purpose of Processing
When Personal Data is no longer necessary for the relevant purpose and no legal or contractualrequirement justifies further retention, it will be deleted or anonymized.
Technical support and software incidents
Security-related information may be retained for a period proportionate to the nature,severity and potential consequences of the security issue concerned.
Personal Data provided to Osborne Systems in connection with a technical support requestor software incident may be used to:
Technical support or complaint records may therefore be retained for an appropriate periodfollowing closure of the relevant request where necessary for service continuity, technical history, security, contractual management or the defence of legal rights.
- identify and understand the issue reported;
- communicate with the person reporting the issue;
- investigate, reproduce, diagnose and resolve technical problems;
- provide technical assistance;
- maintain records of support requests and resolutions;
- improve the reliability, security and performance of Osborne Systems' products and services;
- identify recurring technical issues; and
- protect Osborne Systems' systems, customers and users.
- the nature and complexity of the request or incident;
- whether the matter relates to an existing or prospective customer relationship;
- whether the information remains necessary for technical support or product improvement;
- whether the information is relevant to the security of Osborne Systems' systems or services;
- applicable contractual commitments;
- applicable statutory limitation periods; and
- the need to establish, exercise or defend legal claims.
Product and service information
The applicable retention period may depend on:
Personal Data provided in connection with a request for information may be used to:
Osborne Systems retains Personal Data only for as long as reasonably necessary for thepurpose for which it was collected and in accordance with applicable legal and contractual requirements.
- respond to questions concerning Osborne Systems' products, services or technologies;
- provide relevant technical or commercial information;
- arrange demonstrations, meetings or follow-up discussions; and
- maintain a record of the request where reasonably necessary for future communications.
Retention Period
Product or service complaints
Depending on the circumstances, such safeguards may include an adequacy decision adoptedby the European Commission, Standard Contractual Clauses approved by the European Commission or another legally recognized transfer mechanism.
Personal Data provided in connection with a complaint may be used to:
Where Personal Data is transferred outside the EEA, Osborne Systems takes appropriatemeasures to ensure that such transfers comply with applicable data protection legislation.
- record and acknowledge the complaint;
- investigate the circumstances giving rise to the complaint;
- communicate with the person or organization submitting the complaint;
- assess the technical or operational issue concerned;
- determine and implement appropriate corrective measures;
- identify recurring issues or areas for improvement; and
- establish, exercise or defend legal or contractual rights where necessary.
Certain service providers used by Osborne Systems may process Personal Data outside Franceor the European Economic Area (“EEA”).
Security and vulnerability reports
International Transfers
Where an individual reports a suspected cybersecurity issue, vulnerability, unauthorizedaccess attempt or other security concern, Osborne Systems may process Personal Data in order to:
For further information concerning international transfers and Osborne Systems' generalapproach to Personal Data protection, please refer to the Osborne Systems Privacy Policy.
- investigate and assess the reported security issue;
- communicate with the reporter where additional information is required;
- protect Osborne Systems' information systems, software, infrastructure, customers and users;
- prevent, detect and respond to malicious or unauthorized activity;
- document security incidents and remedial actions; and
- comply with applicable legal or regulatory obligations where relevant.
Third-party service providers processing Personal Data on behalf of Osborne Systems arerequired, where applicable, to process such Personal Data only in accordance with Osborne Systems' instructions and to implement appropriate data protection and security safeguards.
Legal Basis for Processing
- service providers supporting Osborne Systems' IT infrastructure, cloud services, software development, cybersecurity, communications or customer support activities;
- professional advisers where necessary;
- the customer, partner or organization concerned by the request, where appropriate;
- competent administrative, judicial, regulatory or law-enforcement authorities where disclosure is required by applicable law;
- insurers where relevant to a claim or incident; and
- a successor entity in connection with a merger, acquisition, restructuring, financing, sale of assets or other corporate transaction.
Depending on the circumstances, Osborne Systems may process Personal Data on one or moreof the following legal bases:
Depending on the circumstances, Personal Data may also be shared with:
Performance of a contract or pre-contractual measures
Personal Data may be accessed by authorized Osborne Systems personnel where access isnecessary to investigate or respond to the relevant request, issue, incident or complaint.
Where processing is necessary to provide a service requested by an individual who is aparty to a contract with Osborne Systems, or to take steps requested by that individual before entering into a contract, processing may be based on Article 6(1)(b) GDPR.
Recipients of Personal Data
Legitimate interests
Where confidential technical or industrial information must be shared in connection witha customer relationship, such information should be transmitted using the appropriate secure communication channels and will remain subject to any applicable confidentiality agreement or contractual provisions between Osborne Systems and the relevant customeror partner.
Osborne Systems may process Personal Data on the basis of Article 6(1)(f) GDPR where processingis necessary for its legitimate interests, including:
- trade secrets;
- confidential engineering documentation;
- proprietary customer data;
- sensitive operational information;
- credentials or passwords;
- confidential project documentation; or
- Personal Data relating to third parties.
- providing effective technical and customer support;
- responding to professional enquiries;
- managing relationships with customers, prospects and partners;
- investigating and resolving technical issues;
- handling product or service complaints;
- improving its software, products and services;
- ensuring the security, integrity and reliability of its information systems and services;
- preventing fraud, misuse and unauthorized access; and
- establishing, exercising or defending legal claims.
In particular, users should not provide unnecessary:
Where Osborne Systems relies on legitimate interests, it considers whether the processingis necessary and proportionate and whether the rights and interests of the individuals concerned override those interests.
When submitting a support request, incident report or complaint, users should avoid providinginformation that is not necessary for Osborne Systems to process the request.
Legal obligations
Osborne Systems operates in industrial environments where technical information may becommercially sensitive or confidential.
Where Osborne Systems is required by applicable law to process or retain particular information,processing may be based on Article 6(1)(c) GDPR.
Industrial and Confidential Information
Consent
- identity and contact details of the reporter;
- IP addresses and other technical identifiers;
- relevant timestamps;
- security logs;
- details of a suspected vulnerability or incident;
- systems, software or services concerned;
- supporting technical evidence; and
- communications concerning investigation and remediation.
Where applicable law requires consent for a particular processing activity, such processingwill be carried out on the basis of Article 6(1)(a) GDPR.
This may include:
Where processing is based on consent, consent may be withdrawn at any time without affectingthe lawfulness of processing carried out before its withdrawal.
Information relating to security reports
Categories of Personal Data
- description of the complaint;
- relevant product, service, project or functionality;
- dates and circumstances relating to the complaint;
- correspondence relating to the matter;
- supporting documents voluntarily provided; and
- information relating to the resolution of the complaint.
Depending on the nature of the request, incident or complaint, Osborne Systems may processthe following categories of Personal Data.
This may include:
Information about the person making the request or report
Information relating to product or service complaints
This may include:
- description of the technical issue;
- date and time of the incident;
- relevant software or product;
- software version or configuration information;
- account or user identifiers where relevant;
- browser, operating system or device information;
- IP address;
- technical logs;
- error messages;
- diagnostic information;
- screenshots or files voluntarily provided;
- actions performed before or during the incident;
- information regarding the technical environment in which the issue occurred; and
- information necessary to reproduce, investigate or resolve the issue.
- first name and last name;
- professional email address;
- professional telephone number;
- company or organization;
- job title or professional role;
- country or business location;
- relationship with the relevant customer, partner, project or organization; and
- correspondence with Osborne Systems.
This may include: