"Supplier Commitment" Solution
Last updated: November 2023
1. General – The "Supplier Commitment" Solution
Offspend, a company operating under the trade name Greenly, processes your Personal Data (as defined below) for the purposes of supplying the "Supplier Commitment" Solution to its own clients (the "Service").
In order to provide this Service, a questionnaire (the "Questionnaire") is sent to you electronically at the request of Offspend customers who have communicated their wish to engage their own suppliers, with the aim of integrating scope 3 into their GHG report.
On the basis of the answers (or lack of answers) provided in the Questionnaire, Offspend will then be able to award you a "score" (grades ranging from A+ to E), this score indicating the maturity of the carbon strategy that you have implemented as a supplier.
Depending on the score awarded to you, Offspend may also process your personal data for direct marketing purposes, in order to offer you the opportunity to improve your own GHG report by subscribing to Greenly's Carbon Management Platform.
2. General – Information Notice
As data controller, Offspend (Offspend SAS, registered in the Paris Trade and Companies Register under number 878 730 647 and domiciled at 9 rue de Quatrefages, 75005, France,) ("Offspend" or "we") is committed to protecting your privacy as well as the confidentiality and security of your personal data that it processes, in compliance with French law no. 78-17 of 6 January 1978 and its implementing decree no. 2019-536 of 29 May 2019 (the "French Data Protection Act") and European regulation no. 2016/679 of 27 April 2016 (the "General Data Protection Regulation" or "GDPR").
Personal data refers to any information likely to identify you directly (e.g. your name) or indirectly (e.g. your phone number) ("Personal Data").
This information notice ("Information Notice") explains how we process your Personal Data in the context of the Service. We therefore invite you to read the Information Notice carefully.
3. What are the sources of your Personal Data?
We only process the Personal Data that you communicate directly to us when you answer the questions asked via the Questionnaire, which is sent to you at the request of our clients, for the purposes of providing the Service.
4. Characteristics of the processing of your Personal Data
|PERSONAL DATA COLLECTED
|Verifying the reliability of the information provided in the Questionnaire
|Data relating to professional life (position held, name of the company) as well as identification and contact data (surname, first name, professional email address)
|Offspend's legitimate interest
|3 years from their collection or the last contact made with/by you
|Direct marketing by phone
|Identification and contact data (surname, name, professional phone number), language(s) spoken
|Offspend's legitimate interest
|3 years from (i) the last contact made with/by you or (ii) the end of the contractual relationship with you, if you have subscribed to Greenly's Carbon Management Platform
*At the end of these retention periods, your Personal Data, which is strictly necessary, may be archived in an intermediate database for administrative reasons (legal, accounting, tax, etc.). For example, it may be archived for a period of 5 years from the end of the retention period in the active database, for litigation purposes (duration of the statute of limitations), or for 10 years for accounting purposes. At the end of these periods, the data will be deleted from our databases.
5. Do we share your Personal Data?
In order to provide the Service, Offspend may share your Personal Data with the following recipients:
|Trusted service providers
|Categories of trusted service providers: • For the purposes of hosting your Personal Data within our databases during the retention periods described above: your Personal Data is shared with our service provider Heroku, established in Ireland; • For the purposes of our initial contact with you: your Personal Data may be shared with Customer.Io, which hosts it exclusively within the European Union ; • For the purposes of managing our commercial relationship with you: your Personal Data may be shared with HubSpot, which hosts it exclusively within the European Union. Offspend ensures that these third parties implement security measures to guarantee the confidentiality, integrity and availability of your Personal Data.
|Offspend internal services
|Your Personal Data is processed by Offspend's competent internal services based in France
|Administrative and judicial authorities
|Offspend may also be required to disclose your Personal Data when required to do so by judicial and administrative authorities that have a legitimate need to access such information or to allow Offspend to defend its own rights before the competent authorities. In addition, if Offspend is subject to a transfer of a business or assets, we may communicate your Personal Data to the potential buyer of this business or these assets
6. Do we transfer your Personal Data outside the European Economic Area (EEA)?
The Personal Data that we process is exclusively hosted within the European Union.
Should we be required to transfer some of your Personal Data to a recipient located outside the EEA, we will ensure, where applicable, that (i) the service provider is located in a country which benefits from an adequacy decision from the European Commission or (ii) where this is not the case, that appropriate safeguards under the GDPR (i.e., standard contractual clauses adopted by the European Commission) are implemented by Offspend, along with additional technical and organisational security measures
7. What are your rights regarding your Personal Data and how can you enforce them?
As a data subject, you have the following rights:
· a right of access: the right to obtain information on the Personal Data we process about you, for what purposes, for how long, etc., as well as the right to obtain a copy of your Personal Data in an understandable format (proof of your identity may be requested in the event of reasonable doubt);
· a right to rectification: the right to have inaccurate or incomplete Personal Data rectified, completed and/or updated;
· a right to restriction: the right to ask us to restrict one or more processing activities in relation to your Personal Data, in certain cases listed in Article 18 of the GDPR (e.g. while Offspend is processing your objection request);
· a right not to be subject to certain specific processing activities: pursuant to Article 22 of the GDPR, you may ask us not to subject you to a decision based exclusively on automated processing, including profiling, which produces legal effects concerning you or significantly affects you in similar ways;
· a right to object: the right to object to the processing of your Personal Data on grounds relating to your specific situation (under the conditions set out in Article 21 of the GDPR). Where your Personal Data is processed for direct marketing purposes, you may object at any time to such processing, including where it includes profiling activities (to the extent that they are linked to such direct marketing);
· a right to erasure ("right to be forgotten"): the right to ask us to erase your Personal Data in certain circumstances set out in Article 17 of the GDPR. However, we may need to retain your Personal Data in certain specific cases (e.g. to comply with a legal obligation that requires the processing of your Personal Data);
· a right to portability: the right to receive your Personal Data, where it is processed on the legal basis of your consent or if necessary for the performance of a contract, in a structured, commonly used and machine-readable format, and to request that we transfer it to another data controller;
· a right in case of death: in accordance with article 85 of the French Data Protection Act, you have the right to ask us to define directives relating to the preservation, erasure and communication of your Personal Data after your death; and
· the right to lodge a complaint with the supervisory authority, in particular in the country in which you reside or work (if relevant), or in the country where the alleged breach has occurred. In France, the supervisory authority is the Commission nationale de l'informatique et des libertés ("CNIL"), which can be contacted at the following address: CNIL - 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07
To exercise your rights, please contact us directly:
· by post: Paul de Kerret, Data Protection Officer, Greenly (Offspend), 28 rue de Londres, 75009, France.
8. Modification of the Information Notice
In order to keep this Information Notice up to date, Offspend may amend it from time to time. You can find out when it was last updated by referring to the "Last updated" mention at the top of the Information Notice.
When we are considering making substantial changes to this Information Notice (e.g., changes to the processing purposes of the Personal Data), we will inform you before these changes become effective.