PRIVACY POLICY of “STAYING ALIVE” app



Last update: March 5th, 2024

This Staying Alive Privacy Policy applies to data collected and processed within the framework of the "STAYING ALIVE" application. developed and operated by "le Fonds de Développement du Bon Samaritain" (FDBS).

DEFINITIONS

“Data Protection Act” : Law No. 78-17 of January 6, 1978 relating to data processing, files and freedoms, amended by Law No. 2018-493 of June 20, 2018 relating to the protection of personal data .

“Regulation” or “GDPR” : Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of individuals with regard to the processing of personal data and on the free movement of this data (General Data Protection Regulation) and repealing Directive 95/46/EC

.means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing; where the purposes and means of such processing are determined by Union law or the law of a Member State, the controller may be designated or the specific criteria applicable to his designation may be provided for by the law of the Union or by the law of a Member State.

“Processor” means the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

“User” or “Data subject”means any user of the STAYING ALIVE application whose personal data is collected and / or processed.

“Personal Data” means any information relating to an identified or identifiable natural person; is deemed to be an "identifiable natural person" a natural person who can be identified, directly or indirectly, in particular by reference to an identifier, such as a name, an identification number, location data, an online identifier, or to one or more specific elements specific to his physical, physiological, genetic, psychological, economic, cultural or social identity.

“Personal Data Breach”means a breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of personal data transmitted, stored or otherwise processed, or unauthorized access to such data.

"Treatment"means any operation or set of operations whether or not carried out using automated processes and applied to data or sets of personal data, such as the collection, recording, organization, structuring, storage, adaptation or modification, extraction, consultation, use, communication by transmission, dissemination or any other form of making available, reconciliation or interconnection, limitation, erasure or the destruction.

ROLES AND RESPONSIBILITIES OF THE FDBS

The person responsible for processing personal data collected as part of the visit and use of the functionalities of the "STAYING ALIVE" application is the Citizen Responder Development Fund (before and hereinafter "FDBS"). The representative of the data controller is Mr. Paul DARDEL, President of the FDBS. FDBS is a declared endowment fund, registered under number SIREN 840 498 406, whose head office is located at 57, rue du Docteur Blanche 75016 Paris France, and which aims to reduce mortality linked to cardiac arrest thanks to a network of volunteers trained, or not, in life-saving gestures: the Citizen Responders.

INFORMATION ON PERSONAL DATA PROCESSED BY THE FDBS

As part of its activities, the FDBS processes personal data relating to Users of the "STAYING ALIVE" application in compliance with the provisions of the GDPR and the Data Protection Act, in particular with regard to lawfulness, transparency and loyalty. .

A. PERSONAL DATA PROVIDED BY THE USER


All data concerning the persons concerned are collected directly from them through registration forms on the "STAYING ALIVE" application. The FDBS undertakes to inform any user concerned of the procedures for processing their personal data and of their rights in this regard.

B. AUTOMATICALLY COLLECTED PERSONAL DATA


Technical informations. We collect certain device and network connection information when you access our server. This information includes your device model, operating system, IP address and system language. We also collect service, diagnostic and performance information, including crash reports and performance logs. We automatically assign you a user ID.

Location information. We automatically collect information about your location based on your device's GPS data if you enable location services. To learn more about your device's location settings, visit the Help Center.and Apple Support .

C. THE PURPOSES OF PROCESSING PERSONAL DATA


The legal basis for the processing of personal data is the consent of persons voluntarily transmitting their personal information in exchange for information and services necessary for the action of the Citizen Responders. The personal data collected is used within the framework of the services provided by the FDBS. They are used to respond to medical emergencies and vital distress. The FDBS undertakes to collect and process only the personal data strictly necessary for the purposes of the processing and the purposes determined, in compliance with the principle of data minimization.

The processing operations carried out by the FDBS are:

- the creation of the “Citizen Responder” user account required to use the application as a Citizen Responder.

- solicitation of the action of the Citizen Responders following the request of the emergency services (Firefighters and/or SAMU). To do this, the FDBS uses geolocation data to identify the Citizen Responders who are located near the victim's address, which is communicated by the emergency services. Only the last location data is useful for this processing, it is therefore the only one to be kept for a maximum period of 15 days.

- the collection of "log" information to improve the overall operation of the application and in particular its stability on all the devices used by the Citizen Responders.

D. TYPES OF PERSONAL DATA PROCESSED


Personal data is collected by the "STAYING ALIVE" application only from Users who voluntarily register as Contributors or Citizen Responders. Different types of personal data are used depending on the purposes. The list of data collected according to each purpose is described below:

(1) Data entered by the User and sent via the registration form as a Contributor:

• Email address


This data is used to create the account necessary for using the “STAYING ALIVE” application as a Contributor. A Contributor is a user of the defibrillator database within “STAYING ALIVE” application. The information collected allows the FDBS to identify the perpetrators of defibrillator modifications. This data is deleted upon request to close the Contributor account, or after a period of inactivity of the “STAYING ALIVE” application of 18 months.

(2) Data entered by the User and sent via the registration form as a Citizen Responder.


• Surname and First name
• Telephone number
• Date of birth
• E-mail address
• Country - Postal code

These data are used to create the account necessary to use the "STAYING ALIVE" application as a Citizen Responder. A Citizen Responder must hold a diploma course in order to be recognized and participate in resuscitation actions. The information collected allows the FDBS to ensure the proper qualification of the registrants. This data is erased upon request to close the Citizen Responder account, or after a period of inactivity of the "STAYING ALIVE" application of 18 months.

(3) Geolocation data collected and transmitted automatically by the mobile phone (with the User's consent).

• Geolocation of the user of the "STAYING ALIVE" application in the background
• Only the last geolocation data is kept by the “STAYING ALIVE” application. If the application no longer communicates location data, then the last location communicated by the application is automatically erased after 15 days.
In order to be able to request the action of the Citizen Responders following the request of the emergency services (Firefighters and/or SAMU), the FDBS must be able to identify and geolocate the Citizen Responders who are located near the address of the victim, which is communicated by the emergency services. For this, it is necessary that the "STAYING ALIVE" application has the precise location of the Citizen Responder in the background and during its use.

(3) Logs.

• Device IP address
• Brand of the device
• Version of the operating system
• Configuration of the application when using the service
• Time and date

In the event of an error within it, the “STAYING ALIVE” application transmits data and information, called logs, on your phone. These logs allow developers to analyze in depth the problems encountered by the application and thus to propose corrective measures to ensure optimum operation of the application for all users.

E. TERMS AND DURATION OF CONSERVATION OF PERSONAL DATA


A. Hosting of collected data

All personal data collected on the "STAYING ALIVE" application is hosted in Europe by Amazon Web Services

B. Duration of retention of processed personal data

The FDBS only retains Users' personal data for duration necessary for the operations for which they were collected and in compliance with the regulations in force.

The Personal Information collected via the "STAYING ALIVE" application is kept by the FDBS only for the time corresponding to the purpose of the collection as indicated below:

- The information collected to enable the FDBS to ensure the proper qualification of registrants is erased upon request to close the Citizen Responder account, or after a period of inactivity of the "STAYING ALIVE" application of 18 months
- Regarding location data, only the last data is kept, replacing the previous location data. The last location data of each Citizen Responder is kept for a maximum of 15 days.
- Concerning the logs, the information is kept for the time necessary to carry out the necessary corrections, and in all cases for a maximum period of 24 months from their collection.

SHARING AND COMMUNICATION OF PERSONAL DATA

Within the limits of their respective powers and for the purposes mentioned above, the main people likely to have access to the personal data collected on the FDBS website are mainly its own employees and service providers.

The personal data of the persons concerned are not transmitted to commercial or advertising actors.

the FDBS may choose to share or transfer the personal information of its Users as described below:

- the FDBS may disclose the personal data of the data subject (a) to comply with a legal obligation, a legal proceeding, a court order or a legal process served on the FDBS, (b) in the context of a legal investigation , (c) protect or defend the rights or property of FDBS or the Users of the Solution, and/or (d) to investigate or help prevent any potential violation of the law, this Policy or our Terms of Service ;

- the FDBS may share all or part of the personal data of the person concerned with entities belonging to or associated with our structure in compliance with the law and regulations. This personal data may only be processed for the purpose of achieving the purposes described in this Policy.

- the FDBS may share the personal data of the data subject with third party service providers, subcontractors to provide the services offered, to carry out quality assurance tests, to provide technical support, and/or to provide other services (emailing, audience analysis). the FDBS undertakes to require its subcontractors to provide a sufficient level of security with regard to the processing of personal data that they carry out on its behalf.

- the FDBS ensures that its subcontractors are in compliance with the GDPR and that they ensure the confidentiality of your data.

Personal Data Protection Officer

Mr. Paul DARDEL is the Data Protection Officer (DPD) of the FDBS. He is notably in charge of ensuring the compliance of the activities of the Endowment Fund with the new European legal framework of the GDPR and of cooperating with the supervisory authority.

You can contact him using the contact form or by mail at:

FDBS – 57, rue du Docteur Blanche 75016 Paris France

TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES

the FDBS undertakes to protect the personal data of users of the "STAYING ALIVE" application with the implementation of technical and organizational security measures aimed at combating unauthorized disclosure, alteration, use or destruction of the personal data processed.

the FDBS implements all the measures at its disposal to create an environment that preserves the quality, security, confidentiality and integrity of the personal data processed.

the FDBS also uses reasonable technologies to secure the processing of personal data of users of the "STAYING ALIVE" application processed for the purposes described in this policy, in particular: - Access
management;
- Data hosting in Europe by Amazon Web Services;
- Encryption of all connections between the application and the data servers.

However, FDBS cannot insure or warrant against all risks with respect to the security of such personal data. the FDBS does not guarantee that this data cannot be consulted, disclosed, modified or destroyed in the event of a breach of one of our guarantees in the event of breach or negligence on the part of the users, in the event of failure of our hosting service provider data, or from one of our subcontractors.

USER RIGHTS

The FDBS undertakes to guarantee respect for the rights of Users of the "STAYING ALIVE" application in terms of the protection of personal data.

In accordance with the law relating to data processing, files and freedoms of January 6, 1978 as amended, as well as the European regulation relating to the protection of personal data of April 27, 2016, except in the event of limitation, your rights in terms of data are the following:
- Right of access: the right to be informed and to request access to the personal data that the FDBS processes;
- Right of rectification: the right to request the modification or updating of personal data when it is inaccurate or incomplete;
- Right to erasure (right to be forgotten): the right to request the permanent deletion of personal data processed for the purposes described in this policy;
- Right to restriction of processing: the right to request that the processing of all or part of the personal data be temporarily or permanently stopped;
- Right of opposition: the right to refuse the processing of personal data at any time;
- Right to data portability: the right to request a copy of personal data in electronic format and the right to transmit this personal data for use by a third party service;
- Right not to be subject to automated decision-making: the right not to be subject to a decision based solely on automated decision-making, including profiling, in the event that the decision would have a legal effect on you or would produce a similar significant effect.

The user can also inform the FDBS of his desire to define the fate of his personal data after a death. In such a case, the FDBS undertakes to respect the methods of processing this personal data within the limits of the applicable legal obligations. In the absence of specific instructions from the person concerned, the FDBS undertakes to destroy the personal data concerned, unless their retention proves necessary for evidentiary purposes or to meet a legal obligation.

SUPPORT AND CONTACT

If you have any questions or complaints about this policy or our personal data collection or processing practices, or if you wish to report any breach of security to us, please contact us at 57, rue du Docteur Blanche 75016 Paris France or by Email: contact@stayingalive.org

In the event of a complaint, you can choose to contact the French supervisory authority in charge of compliance with the rules on the protection of personal data, the Commission Nationale de l'Informatique et des Libertés (CNIL) :
- By mail: 3 Place du Fontenoy TSA 80715, 75334 Paris, Cedex 07
- By internet: https://www.cnil.fr/fr/plaintes/