Privacy and Data Protection Policy

1. General

ESN France - Buddy System administration (whose registered office is at 50, rue des Tournelles, 75003 Paris, France) (“Buddy System”, “we”, “our” or “us”), acting as data controller, is committed to protecting and respecting your privacy. This notice (the “Privacy Notice”) is designed to tell you about our practices regarding the collection, use and disclosure of information that you may provide via this Platform or our mobile application.


This Privacy Notice (together with our Terms and Conditions, any other documents referred to in it and our Cookie Notice) sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.

2. What information do we collect from you, and for how long?

We may collect and process the following data about you:


2.1. Information you give us.
You may give us information, including information that can identify you (“Personal Data“), when you use our Platforms, by filling in forms on the Platforms (such as the sign-up form), when you enter into any of our competitions, promotions or surveys, when you correspond with us by e-mail or otherwise, and when you report a problem with our Platforms.
The information you give us may include:
2.1.1. Mandatory information required to register for the service we provide on our Platforms or to access other services provided by us, including your name, email address, date of birth, gender, and a password. All these fields are mandatory. Buddy System will not be able to provide you with the services offered on our Platforms if the required information is not provided, consequently you will not be able to register for a user account on our Buddy System;
2.1.2. A photograph;
2.1.3. A postal address;
2.1.4. Your mini-biography;
2.1.5. A record of any correspondence between you and us;
2.1.6. Details of your visits to our Platforms and the resources that you access;
2.1.7. Your replies to any surveys or questionnaires. Such information may be used for analytic & user understanding purposes;
2.1.8. Information we may require from you when you report a problem with our Platforms or our service, such as the subject of your request for support.


2.2. Information we collect automatically
2.2.1. If you sign up via social media authentication methods, Buddy System will access certain Personal Data (e.g. first name, surname, picture, email, number of Facebook friends, etc.) in your social media account pursuant to the applicable terms and conditions of these social media platforms. We may also collect some of your Personal Data when you interact with third party social media features, such as “Like” functions.
2.2.2. With regard to each of your visits to our Platforms we may collect, in accordance with applicable laws and where required with your consent, information relating to the devices you use and the networks you are connected to when using our services. This may include the following information: your IP address, log-in information, browser type and version, browser plug-in types and versions, operating system and platform, advertising identifier, information about your visit including the URL clickstream to, through and from our Platforms, products you viewed or searched for, download errors, length of visits to certain pages, page interaction. We collect this information through the use of various technologies including cookies (for further information please refer to our Cookie Notice).
2.2.3. We also collect aggregated information regarding your activity on our Platforms (such as the amount of rides offered, your message response rate, etc.). Such information may be published on your profile on our Platforms.


2.3. Data retention
2.3.1. Except regarding the categories of Personal Data mentioned in clauses
2.3.2 and 2.3.3 below, your Personal Data will be stored for the duration of your relationship with us and then put beyond use 5 years after your last use of our Platforms, if you did not close your account; 1 year after the closing of your account, except if you received a negative rating or report, in which case your Personal Data is stored for either (i) a 2-year period following the latest negative rating or report, or (ii) 1 year after the closing of your account, whichever is longer.
2.3.2. The following categories of Personal Data may be stored for different durations: Financial data (e.g. payments, reimbursements, etc.) is stored for the duration required by applicable tax and accounting laws; All user-generated content (e.g. comments and ratings) is anonymized but remains available on our Platforms.
2.3.3. In the event that your account is suspended or blocked, we will keep your data between 2 and 10 years, to prevent you from circumventing the rules applying to our Platforms.

3. How do we use information we collect from you?

We will use the information we collect:


PURPOSESLEGAL BASIS
3.1. to carry out our obligations arising from any contracts entered into between you and us and to provide you with the information and services that you requested from us;This processing is necessary for the performance of our mutual contractual obligations.
3.2. to send you service-related information by email and/or text message and/or any other communication means (e.g. survey on your Buddy System experience);This processing is necessary for the performance of our mutual obligations and/or carried out with your consent.
3.3. to enable you to personalise your user profile on our PlatformsThis processing is carried out with your consent.
3.4. to enable you to communicate and interact with other members about our servicesThis processing is necessary for the performance of our mutual contractual obligations and/or carried out with your consent
3.5. to give you access to our support services and to enable you to communicate with our member relations team;This processing is (i) necessary for the performance of our mutual contractual obligations, (ii) carried out with your consent and/or (iii) necessary for the establishment, exercise or defence of legal claims.
3.6. to ensure compliance with (i) applicable laws, (ii) our Terms and Conditions, and (iii) our Privacy Notice. Certain breaches that we regard as inappropriate may lead to the suspension of your account;This processing is necessary (i) for the performance of our mutual contractual obligations, (ii) for compliance with our legal obligations and/or (iii) for the establishment, exercise or defence of legal claims.
3.7. to notify you about changes to our services;This processing is necessary (i) for the performance of our mutual contractual obligations, (ii) for compliance with our legal obligations and/or (iii) the establishment, exercise or defence of legal claims.
3.8. to administer our Platforms and for internal operations, including troubleshooting, data analysis, testing, research, analytic and survey purposes;This processing is based on our legitimate interest (i.e. ensuring the security of our Platforms and improving its features).
3.9. to improve our Platforms to ensure that content is presented in the most effective manner for you and for your device;This processing is based on our legitimate interest (i.e. providing you with meaningful content).
3.10. to allow you to participate in interactive features of our service, when you choose to do so;This processing is necessary (i) for the performance of our mutual contractual obligations and/or (ii) based on your consent.
3.11. as part of our efforts to keep our Platforms safe and secure;This processing is based on (i) our legitimate interest (ensuring the security of our Platforms), (ii) carried out for the establishment, exercise or defence of legal claims and/or (iii) for compliance with our legal obligations.

4. Who are the recipients of the information we collect from you and for which purposes?

4.1. When you use our services, some information about you is shared with the members of our communities (e.g. we give your email and some other information to the members with whom you will be matched). Your profile information can also be accessed by your Buddy Coordinator(s) when matching you or checking up on your experience. Your Buddy Coordinator(s) can be a volunteer from a student association or/and a personnel from your hosting HEI. This person can not access your personal messages on the messaging system, but can write to you there, for pairing purposes.


4.2. We may receive and send information about you, including your Personal Data, if you use any of our Platforms, for the purposes outlined in this Privacy Notice.


4.3. We are also working closely with third parties which may be recipients of your Personal Data such as:


  • our associative partners who are European project platforms and which may provide you with connecting services, such as the connection of the information of your profile, from their project platforms to our Platforms. You are under no obligation to use these services, and they are completely free or charge.
  • our sub-contractors in technical, payment, identity verification and delivery services, or analytics providers.

4.4. We only share your Personal Data with any of these third parties in the following cases:
4.4.1. As part of our rating system, the reviews you write will be published on the Platforms. The reviews including your abbreviated name are visible to all visitors of the Platforms;
4.4.2. We use analytics and search engine providers to assist us in the improvement and optimisation of our Platforms (Sentry and UserReport);
4.4.3. It is explicitly requested by you (e.g. when using social media authentication methods);
4.4.4. Buddy System may also disclose your information if required to do so by law or in a good faith belief that such access, preservation or disclosure is reasonably necessary to (i) respond to claims asserted against Buddy System, (ii) to comply with legal proceedings, (iii) to enforce any agreement with our users such as our Terms and Conditions and our Privacy Notice, (iv) in the event of an emergency involving the danger of public health, death or physical injury to a person (v) in the framework of investigation or (vi) to protect the rights, property or personal safety of Buddy System, its members or others ;


4.5. In accordance with applicable laws and where required with your consent, we may combine information about you, including your Personal Data and cookie information, we send to and receive from our associative partners. We may use this information and the combined information for the purposes set out above.

5. How do we use and moderate your messages?

5.1. We may review, scan, or analyse the messages you exchange with other members of our community through our Platforms for fraud prevention, harassment prevention, service improvement, customer support purposes, enforcement of the contracts entered into with our members (such as our Terms and Conditions). For example, in order to prevent the harassment of one user by another user, we may scan and analyse messages sent through our Platforms to check that they do not include any contact details or references to other Platforms.
5.2. We will never scan or analyse your messages with other members of our community for commercial and advertising purposes. We may use automated methods to carry out moderation of these messages, but no automated individual decision-making is performed in this regard.

6. Is your information being transferred? How and where?

In principle, we store the Personal Data that we hold about you in the European Union (“EU“). However, since for example some of our service providers are based in countries outside of the European Union (“third countries”), we also transfer some of your data to third countries. This may include third countries where the European Commission has not taken the decision that such third country ensures an adequate level of protection (for example the United States). In that case, we ensure that the transfer is performed in accordance with the applicable legislation and that appropriate safeguards have been put in place (especially standard contractual clauses as issued by the European Commission) in order to guarantee a sufficient level of protection of individuals’ private life and fundamental rights.
By sending a request to the Group Data Protection Officer (buddysystem@ixesn.fr), we can provide you with the details regarding such appropriate safeguards (for example, the standard contractual clauses issued by the European Commission).

7. How do we protect your information?

We implement a variety of security measures to maintain safety of your personal information when you access your personal information.

8. What are your rights in respect of your personal data?

Since the General Data Protection Regulation (GDPR) enactment, here are your rights in respect of your personal data.


8.1. You are entitled to receive a copy of your personal data that is in our possession (your right of data access).
8.2 You may request the deletion of personal data or the correction of inaccurate personal data (your right to erasure and rectification). Please note that we may keep certain information concerning you, as required by law, or when we have a legal basis to do so (e.g., our legitimate interest to keep the platform safe and secure for other users).
8.3 You have the right to object at any time (i) to the processing of your personal data for the purpose of direct marketing, or (ii) to the processing of your personal data for other purposes on grounds relating to your particular situation (your right to object to processing). Please note that in the latter case, this right only applies if the processing of your personal data is based on our legitimate interest.
8.4 You have the right to restrict the processing of your personal data (your right to restriction of processing). Please note that this only applies if (i) you contested the accuracy of your personal data and we are verifying the accuracy of the personal data, (ii) you exercised your right to object and we are still considering, as foreseen by the applicable law, whether our legitimate grounds to process your personal data in that case override your interests, rights and freedoms; or (iii) your personal data has been processed by us in an unlawful way but you either oppose the erasure of the personal data or want us to keep your personal data in order to establish, exercise or defend a legal claim.
8.5 You have the right to receive and/or have us transfer to another data controller a subset of personal data, that concern you and that you provided us with, and which we process for the performance of our contract or because you previously consented to it, in a structured, commonly used and machine-readable format (your right to data portability).
8.6 To exercise your rights, please contact the Group Data Protection Officer (see under Article 16).
8.7. You also have the right to make a complaint to the relevant data protection supervisory authority or to seek a remedy through the courts if you believe that your rights have been breached.

9. Cookies & similar technologies

To find out more, please see our Cookie Notice.

10. Confidentiality of your password

Where you have chosen a password which enables you to access certain parts of our Platforms, you are responsible for keeping this password confidential. We ask you not to share this password with anyone.

11. Links to other Platforms and social media

Our Platforms may, from time to time, contain links to and from Platforms of our partner networks and affiliates. If you follow a link to any of these Platforms, please note that these Platforms have their own privacy practices and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any Personal Data to these Platforms.

12. Online privacy policy only

This online privacy policy applies only to information collected through our Platforms and not to information collected offline.

13. Your consent

By using our Platforms, you consent to our privacy policy.

14. Unsubscribe

We will use your email address only to provide you information linked to the Buddy System project and its current events. If at any moment you want to unsubscribe and stop receiving emails linked to the Buddy System, just follow the detailed instructions included at the bottom of each email.

15. Changes to our Privacy Notice

Any changes we may make to our Privacy Notice in the future will be posted on this page. When appropriate, we will notify you or seek your consent. Please check back frequently to see any updates or changes to our Privacy Notice.

16. Contact & Data Protection Officer

If at any time you would like to contact us with your views about our privacy practices, or with any enquiry relating to your Personal Data, please use one of the following means:


  • via email to our Data Protection Officer under buddysystem@ixesn.com;
  • or by letter to:
    ESN France - Buddy System administration
    c/o Data Protection Officer
    50 rue des Tournelles
    75003 Paris (France)