General Data Protection Regulation

The General Data Protection Regulation (GDPR) governs the processing of personal data relating to natural persons. It supports technological developments while protecting the rights of the individuals concerned.

It establishes a framework for controllers and processors, particularly to ensure transparency in processing activities.

Adding features to our products or services

Any new feature that may involve personal data is reviewed by our product teams and our GDPR team to assess its legal feasibility and define appropriate practices. We apply data protection by design and by default.

Data protection by design

Privacy is considered from the outset when designing any product or service that may collect, process or use personal data.

Every project applies the data minimisation principle: only data strictly necessary to provide the service should be collected.

Data protection by default

The highest level of protection must be enabled by default from the design stage of the product or service.

Without any specific action by users, the available measures for protecting data and limiting its collection should remain active.

Measures and rules

Our applications, websites and online services incorporate privacy safeguards from the outset.

We may use pseudonymisation, which separates identifying data from other information while retaining, where necessary, the ability to restore the link securely.

We also use encryption so that data cannot be read without the appropriate decryption key.

Activity logging

We use monitoring and logging tools to maintain control over operations performed on the personal data we process.

SSO

We keep our infrastructure separate from our clients’ infrastructure. Interoperability identifiers enable pseudonymised exchanges and, where required, allow us to rely on our clients’ authentication systems without collecting data other than this technical link.

Awareness

New employees receive awareness training on the main GDPR concepts and how they apply within the company.

Autonomy, reversibility and clarity

We inform clients where their data is hosted and respect their choices regarding location.

We adapt to their data protection rules, particularly concerning log retention periods.

We guarantee clients access to data generated and used as part of our services or software licences.

GraphicStream newsletter management

This section describes the processing used to manage subscriptions to the GraphicStream newsletter, related email messages and unsubscriptions.

Data controller

GraphicStream, a French simplified joint-stock company registered with the Bobigny Trade and Companies Register under number 530 431 840, is the controller for this processing.

Data processed

We limit collection to the information needed to operate the subscription and demonstrate consent:

  • the email address provided;
  • the selected language and the page from which the subscription was requested;
  • the date, version and fingerprint of the consent wording displayed;
  • the subscription status and the dates of request, confirmation, welcome message and unsubscription;
  • the technical message identifiers and delivery statuses provided by our email provider, together with information needed to diagnose a delivery failure.

Purposes of processing

The data is used to verify the address through double opt-in, manage the subscription in the selected language, send the announced news, content and offers, process unsubscriptions, avoid sending to addresses with permanent delivery failures and produce overall operational and deliverability statistics.

Legal basis

Sending the newsletter is based on your consent. Technical operations strictly required to manage that choice, secure the service and maintain a reliable mailing list are performed to implement your request and ensure the service operates correctly.

Recipients and processors

The data is accessible only to authorised GraphicStream personnel and to technical providers required for hosting, storage and delivery, including Microsoft Azure, Azure Cosmos DB and Azure Communication Services.

Depending on service configuration, support operations and Microsoft subprocessors, some data may be processed outside the European Economic Area. Where applicable, such transfers are governed by safeguards required under European law and by the provider’s contractual commitments.

Retention periods

  • A confirmed address is retained while the subscription remains active, until unsubscription or the exercise of a right requiring deletion.
  • An unconfirmed request is not used for any campaign. It is retained only for the period required to validate the subscription and must then be deleted when it is no longer needed.
  • After unsubscription, a permanent delivery failure or a complaint, a minimal record may be retained for as long as necessary to respect the person’s choice, prevent accidental re-enrolment or further delivery, and demonstrate that the request was handled.
  • Technical delivery information is retained for as long as needed for operational monitoring, error resolution and aggregated statistics, then deleted or anonymised when no longer required.

Your rights

You may request access to your data, its correction or deletion, or restriction of processing. You may withdraw your consent at any time without affecting processing carried out before withdrawal. You also have the right to lodge a complaint with the CNIL, the French data protection authority.

Every newsletter contains a personal link allowing you to unsubscribe free of charge, without creating an account or providing a password.

To exercise your rights or ask a question about this processing, write to contact@graphicstream.fr.

Email audience measurement

At launch, GraphicStream does not use invisible pixels to measure individual message openings and does not associate clicks with a personal profile. Measurements are limited to technical delivery results and aggregated campaign statistics.

Automated decision-making

No decision producing legal or similarly significant effects is made automatically from newsletter data, and no individual profiling is performed.

Security

GraphicStream implements appropriate technical and organisational measures, including double opt-in, signed links, access management, encrypted communications and data minimisation. As no system can guarantee absolute security, these measures are reviewed according to risk and changes to the service.

Access to the regulation

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

CNIL logo

Read the GDPR on the CNIL website

Who are we?

Who are we?

Our values, expertise, strengths and team…