Privacy policy

Cofinair blue and red shape

1. Purpose

This privacy policy aims to inform users of the COFINAIR Group website about how their personal data is collected, processed, and protected.

Respect for privacy and personal data is a priority for COFINAIR.

2. Data Controller

Personal data is collected by: COFINAIR.

3. Personal Data

Personal data means any information relating to an identified or identifiable natural person, directly or indirectly, in particular by reference to an identifier (name, number, location data, online identifier) ​​or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

4. Data Collected

The following data may be collected when using the website:

Data provided directly:

  • Position / Role
  • Your company
  • Your first name
  • Your last name
  • Address
  • Zip code
  • Country
  • City
  • Your e-mail
  • Your phone number
  • The reason for your request
  • Your message
  • Your resume
  • The URL of your LinkedIn profile
  • How you heard about Cofinair

Browsing data:

  • IP address (anonymized or pseudonymized depending on the tools)
  • Connection data
  • Pages viewed
  • Date and time of visit
  • Technical data of the browser and device
  • Security logs

5. Purposes of processing

The data collected is used for:

  • Managing requests via forms (contact, information, callback)
  • Customer relationship management
  • Responding to user inquiries
  • Marketing
  • Improving the website and user experience
  • Website security and preventing fraud/abuse
  • Compiling anonymous traffic statistics

6. Legal basis for processing

The processing is based on the following legal grounds:

  • Consent: for forms and non-essential cookies
  • Legitimate interest: for business management, security, and statistics
  • Contractual performance: when a business transaction or relationship is ongoing
  • Legal obligations: when required by regulations

7. Data Hosting

The collected data is hosted within the European Union.

Some data may be processed by technical service providers, acting as data processors, in compliance with the GDPR.

8. Data Recipients

Personal data is intended exclusively for COFINAIR.

It may be transmitted to technical service providers strictly necessary for the operation of the services (hosting, management tools, analytical tools, etc.).

No data is sold or transferred to third parties for commercial purposes.

9. Data Transfer Outside the European Union

As a general rule, data is hosted and processed within the European Union.

If third-party services are used that may involve a transfer outside the EU (e.g., analytical tools, technical services), appropriate safeguards are implemented in accordance with the GDPR (standard contractual clauses, security measures, etc.).

10. Data Retention Period

Data is retained only for the period necessary for the purposes for which it was collected:

  • Data from forms: for the duration necessary to process the request, then archived according to legal obligations
  • Customer data: for the duration of the contractual relationship, then for a limited period
  • Marketing data: limited period in accordance with CNIL recommendations (3 years after the last contact)
  • Browsing data: variable period depending on the cookies and tools used (see the section dedicated to cookies)

11. Data Security

COFINAIR implements appropriate technical and organizational measures to ensure a level of security commensurate with the risks, including:

  • access protection
  • system security
  • data access restrictions
  • vendor oversight
  • internal incident management procedures

12. Data Subject Rights

In accordance with applicable regulations (the GDPR and the French Data Protection Act), you have the following rights:

  • right of access
  • right to rectification
  • right to object
  • right to erasure
  • right to restriction of processing
  • right to data portability

13. Exercising Your Rights

You can exercise your rights by contacting us using the form available on the website.

All requests must be accompanied by a valid form of identification to ensure the security of the processing.

Requests will be processed within a maximum of one month.

14. Right to lodge a complaint

If, after contacting us, you believe that your rights have not been respected, you may lodge a complaint with the competent supervisory authority:

CNIL: https://www.cnil.fr/

15. Browsing data (logs)

When browsing the website, certain technical data may be automatically collected and recorded in log files, including:

  • IP address
  • date and time of connection
  • pages viewed
  • requests made
  • browser technical data

This data is used for security, maintenance, and abuse prevention purposes.

16. Cookies

16.1 Definition

A cookie is an electronic file placed on a device (computer, tablet, smartphone) when visiting a website.

(Source: CNIL)

16.2 Use of cookies

When you browse the site, cookies may be placed on your device in order to:

  • ensure the site functions correctly
  • improve the user experience
  • measure audience
  • offer relevant content

16.3 Managing consent

On your first visit, a banner allows you to accept, refuse, or configure cookies.

Cookies requiring consent are only placed after your explicit agreement.

You can change your preferences at any time.

The validity period of consent is a maximum of 14 months.

16.4 Types of Cookies Used

The site may use:

  • Technical cookies (necessary for operation)
  • Audience measurement cookies
  • Third-party cookies (videos, external tools, analytics, etc.)

16.5 Third-Party Tools

The site may integrate third-party services that may place cookies, such as:

  • Google Analytics (statistics)
  • Video services (YouTube, Vimeo, etc.)
  • Consent Management Platforms (CMP)
  • Translation or optimization tools

These services may process data in accordance with their own privacy policies.

16.6 Cookie Management

You can at any time:

  • configure your browser to accept or refuse cookies
  • delete cookies already installed
  • set up alerts when cookies are placed

Refusing cookies may limit certain site functionalities.

17. Contact

For any questions relating to this privacy policy or the processing of your personal data, you can contact us using the methods available on the site.

Italy

This policy describes how the COFINAIR Group collects and processes the personal data of users of its website, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Italian law. The data processed may include identification and contact information (such as name, surname, company, email address, telephone number), the content of messages submitted via forms, and technical browsing data (IP address, logs, connection data) collected in particular for security, abuse prevention, and anonymized statistical purposes. Providing certain data is necessary to process requests or access certain website features, while other information remains optional. The processing is based on appropriate legal grounds, including the performance of pre-contractual measures at the user’s request, compliance with legal obligations, the legitimate interest of the data controller (in particular for website security and service improvement), and consent where required, especially for the use of profiling cookies. The data is accessible only to authorized internal departments and to technical service providers acting on behalf of COFINAIR, in strict compliance with confidentiality obligations.

Data may, where necessary, be transferred outside the European Union, particularly via hosting services or cloud solutions. In such cases, COFINAIR ensures the implementation of appropriate safeguards, such as standard contractual clauses, to guarantee a level of protection compliant with regulatory requirements. Data is retained for a period strictly proportionate to the purposes for which it is processed, including the time necessary to process requests and maintain the relationship, without prejudice to legal retention obligations.

In accordance with applicable regulations, users have the right to access, rectify, erase, restrict, and object to the processing of their data, as well as the right to data portability. They may also withdraw their consent at any time when processing is based on consent, and lodge a complaint with the competent supervisory authority, in particular the Italian Data Protection Authority (Garante per la protezione dei dati personali).

This website uses cookies and similar technologies to ensure its proper functioning, improve the user experience, and measure audience engagement. Technical cookies are placed without consent, while profiling or third-party cookies require the user’s prior agreement. Settings can be modified at any time via the browser or the consent management tool, although disabling certain cookies may affect the website’s functionality.

COFINAIR implements appropriate technical and organizational measures to guarantee the security, integrity, and confidentiality of personal data and is committed more broadly to compliance, ethics, and continuous improvement, particularly with regard to quality, environmental, and safety requirements.

Finally, in accordance with the obligations stipulated by Italian Legislative Decree No. 24/2023 concerning the protection of whistleblowers, the COFINAIR Group has established an internal mechanism for reporting, confidentially or anonymously, any behavior contrary to the law or the public interest. This system complies with the applicable legal framework, in particular Legislative Decree No. 231/2001, and guarantees the protection of the persons concerned as well as the confidentiality of the information transmitted.

Germany

The protection of personal data is a priority for Cofinair. Data collected via the website is processed in accordance with Regulation (EU) 2016/679 (GDPR) and the German Federal Data Protection Act (BDSG). This data may include information voluntarily provided via forms, as well as technical data collected during browsing, such as IP address, date and time of access, pages visited, or files downloaded, which is generally processed anonymously.

Data processing is based on legal grounds such as the performance of pre-contractual measures, compliance with legal obligations, or legitimate interest, in particular to ensure website security, prevent misuse, and guarantee its proper functioning. The use of security measures, such as reCAPTCHA, may result in additional data processing to distinguish human users from automated systems. Personal data is only transferred to third parties to the extent necessary for processing requests or when required by law, and may be hosted on infrastructure located outside the European Union, subject to appropriate safeguards ensuring its protection.

Data is retained for a period strictly limited to the purposes for which it was collected, subject to legal retention obligations, particularly for accounting purposes. Users have the right to access, rectify, erase, and restrict the processing of their data, as well as the right to object to its processing. They may also withdraw their consent at any time and lodge a complaint with the competent supervisory authority.

Cofinair uses technical cookies necessary for the website’s operation and, subject to user consent, analytics or personalization cookies. These cookies are managed via a dedicated consent tool, in accordance with the requirements of the GDPR and German regulations. In accordance with applicable German legal obligations, particularly those relating to mandatory legal notices (“Impressum”), Cofinair provides users with transparent information regarding the website publisher, its legal representatives, and its administrative identifiers. The company ensures the compliance of its content and prioritizes amicable resolution in the event of a reported non-compliance. Any use of published contact information for unsolicited marketing purposes is strictly prohibited and may be subject to legal action in accordance with applicable law.