Privacy Policy
Data Security – GDPR Personal Data Management Data Privacy Policy
Last updated: August 14, 2026
Part 1 : Telegrafik connected solutions
Généralités
TELEGRAFIK attache une grande importance à la protection des données personnelles de ses utilisateurs et au respect de leur vie privée.
Elle s’engage par ailleurs à se conformer à toute loi ou réglementation relative à la protection des Données Personnelles, notamment le RGPD, et en particulier à prendre toutes les précautions utiles afin de préserver la sécurité et la confidentialité des Données à Caractère Personnel, notamment en empêchant qu’elles ne soient déformées, endommagées ou communiquées à des tiers non concernés.
Les informations recueillies sont strictement limitées à la délivrance des services opérés par Telegrafik sous toutes ses formes.
Telegrafik s’engage, avec ses partenaires, à ce que toutes les informations soient fournies aux personnes concernées, et que le consentement éclairé des bénéficiaires des services soit recueilli lorsqu’il doit l’être. Notamment, en tant que sous-traitant des responsables de traitements clients ou partenaires, Telegrafik fournit des outils et modèles de documents auprès de ses clients et partenaires afin de les aider à respecter au mieux leurs obligations notamment en matière de conformité au Règlement Général de Protection des Données.
Depuis l’entrée en vigueur du RGPD, TELEGRAFIK prend toutes les mesures pour respecter les dispositions du règlement. Afin de garantir toujours plus de sécurité, TELEGRAFIK a choisi de passer en 2020 en hébergement données
de santé, chez l’hébergeur BTBlue (ex Bretagne Telecom).
TELEGRAFIK s’engage à respecter tous les aspects de ses Contrats de Services et Contrats de Partenariats Commerciaux relatifs à la sécurité et à la gestion des données.
Les données personnelles recueillies par Telegrafik
Selon les traitements confiés à Telegrafik par les responsables de traitements clients ou partenaires, Telegrafik peut être amené à traiter les données suivantes au sein de sa plateforme :
Informations directes
Etat civil, Identité, adresse, numéro de téléphone, adresse email, sexe, date de naissance, situation maritale, habitudes de vie, configuration du logement, identité et téléphone des aidants, bénéficiaire ou non de l’APA, images de vidéosurveillance, numéro de chambres
Informations indirectes (via les interfaces logicielles utilisateurs ou aidants) :
Géolocalisation, adresse IP, système d’exploitation, marque du téléphone, écrans de l’application consultés Telegrafik applique le principe de minimisation, visant à ne collecter dans la plateforme que les informations nécessaires à la bonne opération du service concerné. Chaque contrat commercial conclu avec un partenaire ou client
s’accompagne d’une définition des traitements de données personnelles concernées : types données, finalités, destinataires etc.
En fonction des outils Telegrafik utilisés, les mentions d’informations sur les traitements de données personnelles sont apportées lors de votre accès aux outils.
Concernant le site vitrine, les données personnelles traitées sont notamment :
– Formulaire de contact : Nom, prénom, adresse email, numéro de téléphone, message. Ces informations sont traitées afin de répondre à vos contacts et sont conservées pour une durée correspondant aux prescriptions légales, en fonction de l’objet de l’échange.
– Logs et IP : adresse IP. Ces informations sont traitées afin de sécuriser le site et vous assurer une expérience adaptée. Elles sont conservées pour une durée correspondant aux prescriptions légales.
Où sont stockées les données personnelles ?
Les données personnelles recueillies par la plateforme Telegrafik sont stockées majoritairement dans les bases de données de notre hébergeur BTBlue (ex Bretagne Telecom), en France. BTBlue (ex Bretagne Telecom) est un hébergeur certifié hébergement données de santé. Pour certaines solutions spécifiques, elles sont stockées dans un serveur sécurisé en local dans l’établissement client.
Sont-elles stockées en toute sécurité ?
Les données personnelles recueillies sont stockées en toute sécurité, selon l’état de l’art dans le domaine du traitement de données de santé sur le cloud : les serveurs sont sécurisés par des dispositifs de protection (systèmes de firewalls et suivis permanents des flux de données au sein du système logiciel et des applicatifs).
Tous les échanges de données sortant des serveurs sont sécurisés par cryptage (SSL ou Secure Socket Layer). Le responsable de la sécurité des données de TELEGRAFIK est le directeur technique Benoît Vallet. Benoît dispose d’une expérience forte en télécoms / data centers.
Depuis 2018, TELEGRAFIK effectue régulièrement des tests de sécurité sur l’ensemble des flux critiques et interfaçages de la plateforme TELEGRAFIK, ainsi que ses différents services opérés (EDAO, Otono-me, etc…). L’hébergement données de santé a renforcé ces tests.
La durée de conservation des données
La durée de conservation des données varie en fonction des outils utilisés et sont exposées par les responsables de traitement. Les données dépersonnalisées peuvent ensuite être conservées sous cette forme sans limitation de durée à des fins d’optimisation des algorithmes du système intelligent et à des fins de R&D pour le développement de systèmes de prévention de la perte d’autonomie des personnes.
Comment sont utilisées les données recueillies ?
Les données recueillies sont utilisées strictement afin de permettre la délivrance du service concerné par le contrat conclu entre Telegrafik et son client ou partenaire.
Comment accéder aux données personnelles recueillies ?
Les utilisateurs disposent d’un droit d’accès, de modification, suppression ou de portabilité de leurs données personnelles sur simple demande, par quelque canal que ce soit, auprès du client ou partenaire responsable du service fourni (ehpad, téléassisteur,…) ou directement auprès de Telegrafik sur demande à dpo@telegrafik.eu.
Telegrafik s’emploie à répondre de manière réactive à toute demande formulée directement auprès d’elle ou auprès de son client ou partenaire.
En tant que client ou partenaire de TELEGRAFIK, quelles sont mes obligations ?
Pour les partenaires sous-traitants : TELEGRAFIK s’assurera auprès de vos services que vous êtes en conformité avec la réglementation RGPD avant toute conclusion de contrat et que vous maintenez le respect de vos obligations tout au long de celui-ci.
Pour les partenaires intégrateurs, clients ou partenaires : Vous êtes interlocuteur des abonnés / bénéficiaires. A ce titre, vous devez respecter vous-mêmes la réglementation RGPD, et notamment recueillir le consentement des abonnés / bénéficiaires lorsque nécessaire, leur fournir toutes les informations légales concernant l’ensemble des traitements de données qui sont opérés et tenir à jour une documentation RGPD conformément à la réglementation. En tant que Sous-traitant ou partenaire, Telegrafik vous accompagne et vous fournit toute l’assistance nécessaire concernant ses Services, avec des outils et modèles de documents notamment.
Part 2 : Showcase website privacy policy
1. Purpose and Scope
This policy describes how TELEGRAFIK processes the personal data of individuals who visit the www.telegrafik.fr/en website, fill out a form, or download a document on it.
It applies solely to the showcase website. It does not cover:
- The processing carried out by TELEGRAFIK as a data processor on behalf of its clients and partners (nursing homes [EHPAD], home care services, telecare operators, landlords, local authorities) as part of its connected solutions. This processing is defined, for each client or partner, in the personal data protection annex of the contract concluded with them, which specifies the categories of data, purposes, retention periods, recipients, and applicable security measures. Beneficiaries and their caregivers are informed of this processing by the relevant data controller, meaning the establishment or organization providing the service to them;
- The authenticated portals accessible from the website (Professional Portal and Personal Portal), which are hosted on separate domains and governed by their own terms and privacy notices.
2. Who is Responsible for Your Data
The data controller for the data collected on the showcase website is:
TELEGRAFIK, 15 chemin de la Crabe, 31300 Toulouse, France.
TELEGRAFIK has appointed a Data Protection Officer (DPO), who can be contacted at dpo@telegrafik.eu or by mail at the head office address, to the attention of the Data Protection Officer.
3. Processing Carried Out on the Showcase Website
3.1 Responding to Contact Requests
Processed data: Last name, first name, email address, phone number, message content, and date of the request.
Purpose: To receive, qualify, and process your request, and to communicate with you regarding it.
Legal basis: TELEGRAFIK’s legitimate interest in responding to the inquiries addressed to it (Article 6(1)(f) of the GDPR).
Mandatory nature: The last name, email address, and message fields are necessary to process your request. Otherwise, TELEGRAFIK will not be able to respond. The other fields are optional and are only used to facilitate further contact.
Retention period: 3 years from the last contact with you, followed by deletion or intermediate archiving when required by a legal obligation.
3.2 Downloading Documentation and Accessing Webinar Replays
Processed data: Last name, first name, professional email address, company or organization, job title, and phone number (if you choose to provide it).
Purposes:
- To send you the requested document or access to the content;
- To send you information about TELEGRAFIK’s solutions, publications, and events, and to allow its sales team to contact you in a professional context.
Legal bases: The performance of pre-contractual measures taken at your request for the first purpose (Article 6(1)(b) of the GDPR), and TELEGRAFIK’s legitimate interest in promoting its solutions to industry professionals for the second (Article 6(1)(f) of the GDPR). This prospecting is exclusively aimed at professionals, in accordance with Article L34-5 of the French Postal and Electronic Communications Code.
Mandatory nature: The last name, first name, email address, company, and job title fields are required to send you the document. Otherwise, the download cannot be completed. The phone number is optional.
You can object to receiving commercial communications at any time, without having to provide a reason, by using the unsubscribe link in each message or by writing to dpo@telegrafik.eu. This objection does not affect the transmission of the document you requested.
Retention period: 3 years from your last contact, meaning the last download, the last opening of a message, or the last interaction with the sales team.
3.3 Website Audience Measurement
Processed data: Visitor ID assigned by the measurement tool, pages viewed and timestamp, referring page that led to the website, duration of the visit, truncated IP address, browser type and version, operating system, screen resolution, and display performance indicators.
Purpose: To compile traffic statistics with the aim of improving your experience on the site and measuring its performance.
Legal basis: Your consent, collected via the tracker management banner displayed during your first visit (Article 82 of the French Data Protection Act). No audience measurement data is collected until you have accepted the “Statistics” category.
Tool used: Matomo, installed and operated on the site’s servers. The data is not cross-referenced with other processing, nor is it transmitted to third parties or used to track you across other websites.
You can withdraw your consent at any time via the “Manage Consent” button at the bottom of each page.
Periods: The lifespan of audience measurement trackers is limited to 13 months and is not automatically extended. Traffic data is kept for a maximum of 25 months, then deleted or aggregated in a form that no longer allows re-identification.
3.4 Tracker Management and Proof of Consent
Processed data: Technical identifier of the choice expressed, categories of trackers accepted or refused, date and time of the choice, and version of the policy in force at the time of the choice.
Purpose: To respect your choice during your subsequent visits and to be able to prove that this choice was collected.
Legal basis: Compliance with a legal obligation to demonstrate the collection of consent (Article 7(1) of the GDPR) and the legitimate interest in ensuring the proper functioning of the collection mechanism.
Retention period: Your choice is kept for 6 months, after which the banner will be presented to you again. Proof of consent is kept for 3 years, in accordance with the CNIL’s recommendation.
Details of the trackers placed, their issuer, their purpose, and their duration can be found in the cookie policy, accessible from the footer of each page on the site.
3.5 Site Security and Protection Against Automated Use
Processed data: IP address, date and time of requests, pages accessed, user agent, as well as technical data processed by the bot protection service for forms (cursor movements, typing speed, technical browser signals).
Purposes: To ensure the availability and integrity of the site, prevent and detect intrusion attempts, denial of service attacks, and automated form submissions.
Legal basis: TELEGRAFIK’s legitimate interest in protecting its information system and the people who use it (Article 6(1)(f) of the GDPR).
Retention period: Technical logs are kept for [6 months]. Identification data is kept for 12 months when a legal retention obligation applies.
3.6 Managing Requests to Exercise Rights
The data you provide to exercise your rights (identity, contact details, subject of the request, any supporting documents provided) is processed to review and document your request, based on the legal obligation resting on TELEGRAFIK (Article 6(1)(c) of the GDPR). It is kept for 1 year from the closure of the request, or 3 years if an appeal remains open.
4. Origin of the Data
All data processed in connection with the showcase website is collected directly from you, either because you enter it into a form or because it is generated by your browser during your visit. TELEGRAFIK does not collect any data from third parties for the showcase website, does not enrich files, and does not acquire prospecting lists.
5. Who Has Access to Your Data
Your data is intended for TELEGRAFIK’s internal departments on a need-to-know basis, namely the sales, marketing, and technical teams, within the limits of their respective duties.
In particular, it may be communicated to the following categories of recipients acting as data processors and bound to TELEGRAFIK by a contract compliant with Article 28 of the GDPR: Hosting provider, cyberattack protection solution, audience measurement tool, communication sending tool, and commercial contract management tool.
Your data is not sold, rented, or exchanged for commercial purposes.
Finally, it may be communicated to any authorized administrative or judicial authority that requests it under the conditions provided by law.
6. Transfers Outside the European Union
Certain service providers used for content delivery and bot protection for forms may process data from the United States.
These transfers are governed by the standard contractual clauses adopted by the European Commission on June 4, 2021, supplemented by the additional measures recommended by the European Data Protection Board, and, where applicable, by the provider’s certification under the Data Privacy Framework (adequacy decision of July 10, 2023).
A copy of the safeguards put in place can be obtained upon request at dpo@telegrafik.eu.
Outside of these cases, the data collected via the showcase website is hosted and processed within the European Union.
7. Security
TELEGRAFIK implements appropriate technical and organizational measures to preserve the confidentiality, integrity, and availability of data. This includes TLS protocol encryption for exchanges, restricting access strictly to authorized personnel, logging access, regularly updating website components, and conducting periodic security tests.
Data security is the responsibility of TELEGRAFIK’s technical department.
8. Your Rights
In accordance with Articles 15 to 22 of the GDPR, you have the following rights regarding your data:
- Right of access: To obtain confirmation as to whether your data is being processed and to receive a copy of it;
- Right to rectification: To have inaccurate or incomplete data corrected;
- Right to erasure: To request the deletion of your data, in the cases provided for by the regulation;
- Right to restriction of processing: To request the temporary freeze of the use of your data;
- Right to object: To object, for reasons relating to your particular situation, to processing based on legitimate interest. Regarding commercial prospecting, this right can be exercised without having to provide a reason;
- Right to data portability: To receive the data you have provided in a structured, machine-readable format, or to request its transmission to another organization, for processing based on consent or a contract;
- Right to withdraw your consent at any time, for processing that depends on it, such as audience measurement. Withdrawal does not affect the lawfulness of processing carried out prior to it;
- Right to set guidelines regarding the fate of your data after your death, in accordance with Article 85 of the French Data Protection Act (loi Informatique et Libertés).
How to exercise your rights: Send your request to dpo@telegrafik.eu, or by mail to TELEGRAFIK, Data Protection Officer, 15 chemin de la Crabe, 31300 Toulouse, France.
As a general rule, no supporting document is required. Proof of identity will only be requested if there is reasonable doubt about the identity of the requester, and it will be destroyed as soon as the request is closed.
Response time: TELEGRAFIK will respond within one month of receiving the request. This period may be extended by two months in the case of a complex request or a high number of requests, in which case you will be informed within the first month of your request, along with the reasons for the extension.
Free of charge: Exercising your rights is free of charge. A reasonable fee may only be charged in the event of manifestly unfounded or excessive requests, particularly due to their repetitive nature.
Complaint: If you believe, after contacting us, that your rights have not been respected, you can file a complaint with the French Data Protection Authority (CNIL):
CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
Phone: +33 (0)1 53 73 22 22
9. Automated Decision-Making and Profiling
None of the processing described in this policy results in a decision producing legal effects concerning you or similarly significantly affecting you based solely on automated processing, within the meaning of Article 22 of the GDPR.
The algorithmic processing implemented by TELEGRAFIK as part of its connected solutions, particularly the detection and prevention models intended for its clients and partners, are unrelated to the showcase website. They fall under the processing carried out as a data processor mentioned in point 1 and are described in the corresponding contractual annexes, as well as in the information provided to the beneficiaries by the relevant data controller.
10. Minors
The showcase website is intended for professionals and adults. It is not intended for minors, and TELEGRAFIK does not knowingly collect their data through this channel. If you notice that a minor has submitted data via a form on the site, you can inform the Data Protection Officer, who will proceed with its deletion.
11. Amendments to This Policy
TELEGRAFIK may update this policy to reflect changes in its processing activities, its tools, or the applicable regulations. The applicable version is the one published on this page, with the update date listed at the top of the document. Previous versions are kept and can be provided upon request at dpo@telegrafik.eu.