Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, known as the General Data Protection Regulation (GDPR), sets out the legal framework applicable to the processing of personal data.
As part of this, we present the procedures for complying with this regulation, in accordance with its requirements. UNIRESI does indeed manage personal data in the course of its business. This activity mainly involves helping students or their relatives to find accommodation (student residences, coliving, etc.).
The information relating to the management of personal data, in accordance with the regulations, is as follows:
UNIRESI makes every effort to comply with regulations when collecting and processing personal data:
Clients and contacts have the right to request UNIRESI to respect their rights with regard to data concerning them. These rights include the following:
When a person provides information (surname, first name, telephone number, e-mail address, location of search, urgency, etc.) on one of our websites, by e-mail or otherwise, to enable UNIRESI to assist him/her in the search for establishments and to call him/her back, he/she is explicitly giving his/her consent to the processing of the personal data he/she has provided and to that which he/she will subsequently communicate to our advisers or to any other UNIRESI employee during telephone conversations and exchanges of computer or telephone data (e-mail, sms, WA, etc.).
Any person has the right, at any time, to request the withdrawal of his or her consent to the processing of his or her personal data, in accordance with the regulations. UNIRESI undertakes to comply strictly with this right as soon as possible.
UNIRESI informs its clients and contacts that it may involve any subcontractor of its choice in the processing of their personal data.
In this case, UNIRESI shall ensure that the subcontractor complies with its obligations under the GDPR, whether or not it is located within or outside the European Union.
UNIRESI undertakes to sign a written contract with all its subcontractors and imposes the same data protection obligations on subcontractors as it does itself. In addition, UNIRESI reserves the right to audit its subcontractors in order to ensure compliance with the provisions of the GDPR.
UNIRESI defines and implements the physical or logical technical security measures that it deems appropriate to prevent the accidental or unlawful destruction, loss, alteration or unauthorized disclosure of data.
These measures mainly include :
In the event of a breach of personal data, UNIRESI undertakes to notify the CNIL in accordance with the conditions prescribed by the GDPR.
If such a breach gives rise to a high risk for clients and contacts and the data has not been protected, UNIRESI :
UNIRESI has appointed a Data Protection Officer.
The contact details for the Data Protection Officer are as follows:
Alain Boublil
UNIRESI - Retraite Plus
14, Quai de la Marne 75019 Paris
Email: donnees-personnelles@retraiteplus.fr
Tel: 0800941340
In the event of any new processing of personal data, UNIRESI will first refer the matter to the Data Protection Officer.
If clients and contacts wish to obtain specific information or ask a specific question, they may refer the matter to the Data Protection Officer, who will provide a response within a reasonable period of time in relation to the question asked or the information required.
In the event of a problem with the processing of personal data, customers and contacts may contact the designated Data Protection Officer.
UNIRESI , as data controller, undertakes to keep an up-to-date register of all processing activities carried out.
This register is a document or application making it possible to list all processing carried out by UNIRESI , as data controller.
UNIRESI also undertakes to prepare an Impact Analysis of the risks relating to personal data.
UNIRESI undertakes to provide the supervisory authority, upon first request, with the information enabling the said authority to verify that the processing complies with the data protection regulations in force.
Customers and contacts concerned by the processing of their personal data are informed of their right to lodge a complaint with a supervisory authority, namely the CNIL in France, if they consider that the processing of their personal data does not comply with European data protection regulations, at the following address: