PRIVACY POLICY
(Last updated: september 2024)
This document is a translation of the original French version. In the event of discrepancies, the French version shall prevail. French law takes precedence over any English law.
OORION, a Simplified Joint Stock Company registered in the Trade and Companies Register of VERSAILLES under number B 888 454 212, with its registered office at 16 rue Cuvier 69006 LYON - France (hereinafter the "Company" or "OORION") is committed to ensuring that the Processing of Personal Data carried out on the OORION application it publishes (hereinafter the "Application") complies with applicable data protection regulations (General European Regulation 2016/679 on Data Protection - "GDPR") and the French Data Protection Act No. 78-17 of January 6, 1978, as amended.
The Application allows its Users to search for and identify objects and texts present in their immediate environment.
The purpose of this Privacy Policy is to inform any User of the Application about how OORION collects and processes the Personal Data concerning them. The Personal Data collected by OORION is used to operate the Application and to improve it.
OORION is the Data Controller for the Personal Data collected via the Application.
ARTICLE 1 - DEFINITIONS
PERSONAL DATA Refers to any information that directly or indirectly allows the identification of a natural person.
IMAGES Refers to the images captured by the Application when using the Services.
OBJECTS Refers to the objects identified on the Images when using the Services.
DATA SUBJECT Refers to any natural person whose Personal Data is collected and processed by OORION.
DATA CONTROLLER Refers to the person who determines the purposes and means of Processing. OORION Company has this quality within the framework of this Privacy Policy.
PROCESSOR Refers to the person who processes Personal Data on instruction from the Data Controller as part of a service or provision. The list of processors concerned is provided below.
SERVICES Refers to the services offered by the Application.
PROCESSING Refers to any operation or set of operations performed using automated or manual processes on an electronic or paper medium, such as the collection, recording, organization, structuring, storage, adaptation or modification, retrieval, consultation, use, disclosure by transmission, dissemination of Personal Data.
USER Refers to any person who uses the Application and who uses the Services offered therein. The User has the quality of Data Subject.
ARTICLE 2 - PROCESSING OF PERSONAL DATA AND PURPOSES
OORION processes and collects Personal Data:
- That the User provides directly to the Company. This is the email address provided by the User when subscribing to the newsletter.
- That OORION automatically collects through cookies or other analysis tools. For example, this may include the User's IP address, browser, and device. This information is used to improve the Application.
a. Processing n°1: The Processing is aimed at the proper functioning and continuous improvement of the Application and its Services
It allows:
- The use of Services;
- Technical administration in connection with technical providers and internal services in charge (development, hosting, support, maintenance);
- Improvement of Services;
- Management of Application security to ensure its proper use.
Legal bases of Processing:
Article 6 (1) f) of the GDPR: Processing is necessary for the purposes of the legitimate interests pursued by OORION;
Article 6 (1) a) of the GDPR: The Data Subject has consented to the Processing of his or her Personal Data.
Categories of Personal Data processed:
- Connection data: Device type, country and date of connection, Application version, Application usage event (opening, use of a feature, texts searched by the User), event logs.
Data Subjects:
Users of the Application
Automated decision-making
The Processing does not provide for automated decision-making.
b. Processing n°2: The Processing is aimed at managing the OORION newsletter sent to registered Users
It allows:
- Preparing the content of the newsletter;
- Managing newsletter subscriptions;
- Managing electronic mailings;
Legal basis of Processing:
Article 6 (1) a) of the GDPR: The Data Subject has consented to the Processing of his or her Personal Data.
Category of Personal Data collected:
- Identification data: Email address of the Data Subject
Data Subjects:
Users of the Application
The Personal Data collected for the realization of this purpose is collected on a mandatory basis.
Automated decision-making:
The Processing does not provide for automated decision-making.
c. Processing n°3: The Processing is aimed at managing requests for the exercise of Data Subjects' rights
It allows:
- Receiving requests for exercise via the dedicated email address;
- Investigating and monitoring requests;
- Managing the history of requests and responses provided to requesters;
Legal basis of Processing:
Article 6 (1) c) of the GDPR: Processing is necessary for compliance with a legal obligation to which OORION is subject.
Category of Personal Data collected:
Identification data: Name, first name, email address of the Data Subject and possibly their identity card in case of doubt about the identity of the requester
Data Subjects:
Users of the Application
The Personal Data collected for the realization of this purpose is collected on a mandatory basis.
Automated decision-making:
The Processing does not provide for automated decision-making.
ARTICLE 3 - COLLECTION OF ANONYMIZED DATA
To provide you with efficient Services, the Application's algorithm collects and records Images emitted from your smartphone's camera when you use the Services only.
The Application also allows any User to save Objects in a library by giving them a name.
Images may display Personal Data such as faces when scanning the room or personal documents (national identity card, passport, letters, etc.) when using the Object reading feature.
OORION is committed to protecting the Personal Data of individuals (Users and non-users) by not processing or retaining Images or Objects containing Personal Data.
For this purpose, the concerned Images will neither be stored on external servers nor present on your smartphone locally: they will be automatically deleted after local processing.
ARTICLE 4 - RECIPIENTS OF PERSONAL DATA AND THIRD-PARTY SERVICES
The Personal Data collected via the Application is intended for internal services of OORION Company. However, some of this Personal Data is intended for Processors and third-party distribution partners of OORION.
Moreover, some Processors may collect other Personal Data in connection with the service they provide to OORION.
In particular, if the user activates the option in the settings and consents to the terms of use, images captured by the Application may be transmitted to a third-party OpenAI service. The user may deactivate this option at any time in the application settings.
All concerned Personal Data is listed below. We invite you to read the privacy policy specific to each Processor to obtain more information (the link to access these policies is provided below).
The internal services of the Company have access to Personal Data strictly collected by OORION and are subject to confidentiality obligations.
These include:
- OORION personnel responsible for supervising the security of OORION's information systems and more generally for managing the Application;
- OORION personnel in charge of Processing support requests received by email via the Application's contact feature;
- OORION personnel in charge of Processing requests made by telephone directly from the Application;
| Name of third-part y service | Company name and address of registered office | Processing purposes | Data that may be directly collected by the third-party service | Link to the privacy policy |
|---|---|---|---|---|
| Google Cloud Platform | Google Ireland Limited, a company registered in Ireland whose principal place of business is at Gordon House, Barrow Street, Dublin 4, Ireland | - Develop the Application - Host and make the Application and all its functionalities available to Users, - Analyze the use of the Application, - Improve the Application | Device type, country and date of connection, Application version, Application usage event (opening, use of a feature, texts searched by the User), IP address, event logs | Accessible by clicking here. |
| Google Analytics | Google Ireland Limited, a company registered in Ireland whose principal place of business is at Gordon House, Barrow Street, Dublin 4, Ireland | - Analyze the use of the Application - Improve the Application | Device type, country and date of connection, Application version, Application usage event (opening, use of a feature, texts searched by the User), IP address, event logs | Accessible by clicking here. |
| Google Firebase | Google Ireland Limited, a company registered in Ireland whose principal place of business is at Gordon House, Barrow Street, Dublin 4, Ireland | - Analyze the use of the Application - Improve the Application | Device type, country and date of connection, Application version, Application usage event (opening, use of a feature, texts searched by the User), IP address, event logs | Accessible by clicking here. |
| MixPanel | MIXPANEL S.L, Avenida Diagonal, 442 – P. 3 PTA. 1 08037, Barcelona, Spain. | - Analyze the use of the Application - Improve the Application | Device type, country and date of connection, Application version, Application usage event (opening, use of a feature, texts searched by the User), IP address, event logs | Accessible by clicking here. |
| MailChimp | Intuit Data Protection Administration 7 rue de la Paix 75002 Paris, France | Sending and managing the newsletter | Name, first name, email address | Accessible by clicking here. |
| OpenAI API (optional based on user’s choice) | OpenAI, Inc. 3180 18th St, San Francisco, CA 94110, United States of America. | Improve image descriptions and provide better guidance instructions. | Images captures by the smartphone’s camera. | Accessible by clicking here. |
OORION guarantees to any User that the Processors it uses in the context of the Application and the partners with which it collaborates provide sufficient guarantees regarding the implementation of appropriate technical and organizational measures so that the Processing meets the requirements of the GDPR and guarantees the protection of Users' rights.
OORION commits to ensuring that your Personal Data collected and processed by OORION is hosted on a health data approved host that presents security and confidentiality conditions in accordance with applicable data protection regulations (General European Regulation 2016/679 on Data Protection - "GDPR") and the French Data Protection Act No. 78-17 of January 6, 1978, as amended.
ARTICLE 5 - TRANSFERS OF PERSONAL DATA OUTSIDE THE EU
OORION does not organize transfers of Personal Data outside the EU.
Its processors may have servers outside the EU. It is therefore possible that some Personal Data is processed by servers located outside the EU, in a third country.
In the event of transfer of all or part of the Personal Data subject to Processing to a third country, i.e., located outside the European Union or not presenting a level of protection recognized as adequate within the meaning of the regulations, or to an international organization, OORION undertakes to provide the appropriate guarantees provided for in the regulations and to have them respected by its Processors.
ARTICLE 6 - RETENTION PERIOD OF PERSONAL DATA
- Personal Data collected to analyze and improve the Application is kept only for a maximum period of 25 months;
- Personal Data relating to connection logs is kept for six months;
- Personal Data collected through cookies is kept for a maximum of 25 months;
- Personal Data provided when subscribing to the newsletter is kept as long as the User has not unsubscribed from the newsletter;
- Images collected by the Application are kept in a format that does not allow the identification of individuals. They are anonymized.
ARTICLE 7 - SECURITY MEASURES
OORION commits to implementing:
- Physical security measures aimed at preventing access to Personal Data by unauthorized persons;
- Identity and access controls via an authentication system as well as a password policy;
- A system for managing authorizations;
- Processes and devices to trace all actions carried out on the information system and to perform, in accordance with regulations, reporting actions in the event of an incident impacting Personal Data.
ARTICLE 8 - MINORS
In accordance with the provisions of Article 8 of the GDPR and the amended French Data Protection Act, only minors aged 15 or over can consent to the Processing of their Personal Data.
If the User is a minor under 15 years of age, the authorization of the holder of parental authority will be requested so that Personal Data can be collected and processed.
OORION reserves the right to verify by any means that the User is over 15 years of age or that they have obtained the authorization of the holder of parental authority.
ARTICLE 9 - EXERCISE OF RIGHTS
In accordance with the provisions of the amended French Data Protection Act and the GDPR, you have the right of access, rectification, erasure, limitation, opposition, and a right to the portability of Personal Data concerning you. To exercise all these rights, we invite you to send your request to the following email address: contact@oorion.fr.
a. Right of access
You have the right to access Personal Data concerning you processed by OORION. It allows you to be aware of the Personal Data we have about you and, if you wish, to request a copy.
b. Right to rectification
Under the applicable regulations on the protection of Personal Data, you can request from us the rectification of inaccurate Personal Data concerning you. You can also request that incomplete Personal Data concerning you be completed, including by providing, in support, a complementary declaration.
If you believe that other Personal Data concerning you should be modified or completed and you are unable to make this change yourself, we invite you to contact us at the following address: contact@oorion.fr
c. Right to erasure
You have the right to obtain from us the erasure, as soon as possible, of Personal Data concerning you, subject to our legitimate interest or any legal obligation requiring us to retain it.
For security reasons, we invite you to carry out this process by contacting us at the following address: contact@oorion.fr
d. Right to restriction of Processing
You can request OORION to restrict the Processing of your Personal Data when one of the following elements applies:
- you contest the accuracy of the Personal Data concerning you. In this case, we will mask the Personal Data concerning you, for a period allowing us to verify its accuracy;
- you consider that the Processing of your Personal Data is carried out unlawfully and you require instead the restriction of their use;
- we no longer need the Personal Data concerning you for the purposes of Processing but it is still necessary for you to establish, exercise or defend legal claims;
- you have exercised your right to object under Article 21, paragraph 1 of the GDPR.
We will proceed with the restriction of Processing of your Personal Data, during the verification of whether the legitimate grounds we pursue prevail over your right.
If we decide to lift the restriction of Processing of your Personal Data, we will keep you informed.
e. Right to object
You can object to the sending of communications, particularly commercial ones, by OORION. For this purpose, we provide you with an unsubscribe link in all emails we send you.
You can also object, for legitimate reasons, to the Processing of your Personal Data, unless it responds to a legal obligation imposed on OORION.
f. Right to data portability
You can at any time request the portability of your Personal Data to OORION. By exercising this right, we commit to transmitting to you within a reasonable time and in a machine-readable format the Personal Data that you have provided to us, whether declared by yourself or generated by your activity on the Application.
g. Right to withdraw consent
When the Processing of Personal Data is based on your consent, you have the right to withdraw it at any time. You will no longer be able to use the Application in this case.
h. Right to lodge a complaint with a supervisory authority
The competent supervisory authority to handle any request concerning us, including, where applicable, a User's complaint, is the French Data Protection Authority (CNIL).
If you wish to refer a matter to the CNIL, you will find the contact details below:
CNIL (COMMISSION NATIONALE DE L'INFORMATIQUE ET DES LIBERTÉS) 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07 Tel.: 01 53 73 22 22 (Monday to Thursday from 9am to 6:30pm / Friday from 9am to 6pm) Fax: 01 53 73 22 00
Attention! The CNIL does not receive the public and does not provide any information on site.
If you wish to file a complaint with the CNIL, you can fill out the online complaint form available at the following address: https://www.cnil.fr/en/plaintes
If you have a question about your computer and freedom rights, you can consult the CNIL website: www.cnil.fr.
COOKIE POLICY
Browsing the Application may cause the installation of cookies on the User's terminal (by the Company and/or its Processors). You are asked to set your choices regarding cookies when you connect to the Application.
a. Definition
A cookie is a small text file, deposited on your terminal, via the internet browser, for example when visiting a website, reading an email, installing software, etc.
A cookie does not allow the identification of the User but records information relating to their navigation.
b. Types of cookies used
The different types of cookies and their purposes:
Consultation of the Application results in the deposit of cookies by OORION on your terminal in order to simplify and improve your navigation on the Application and to personalize the Services under the conditions defined below.