Passer au contenu

ALMA – Personal Data Protection Policy

Last updated: 09/04/2026

1) Data Controller and Contact Details

Data Controller:
Chaumet International SA (hereinafter, "CHAUMET"), a public limited company (société anonyme) with its registered office at 12 place Vendôme, 75001 Paris (France), registered with the Paris Trade and Companies Register under number B 342 966 942. DPO Contact: privacy@chaumet.com

2) Scope

This information notice explains how CHAUMET collects and uses personal data in connection with the use of its e-learning application ALMA (hereinafter, the "Application") for the delivery and administration of training, progress tracking, and assessments.

3) Personal Data Processed

We may process the following categories of personal data:

Identification and employment data

First and last name, employee ID, professional contact details

Job title, department/service, workplace, manager/line manager

Training and assessment data

Assigned training, training paths, attendance/participation

Completion status, certifications (if applicable)

Assessment results (e.g., test scores) and assessment data related to the training

Technical logs and usage data

Account IDs, login/logout events, timestamps

IP address, device/browser information, application version

Security and audit logs, error logs, basic usage events necessary for support and security

4) How we collect your data

From you when you use the Application (e.g., completing modules, taking assessments)

From employee files in order to provision access and assign training (e.g., identity, role, reporting line)

Automatically via the Application (technical logs and security/audit trails)

5) Purposes of processing

We process personal data in order to:

Provide and administer the Application (access management, account management, training assignment)

Organize and manage training programs (including mandatory training if applicable)

Assess knowledge and training completion (tests, completion tracking)

Produce training-related reports for HR and authorized management

Ensure the security and proper functioning of the Application (fraud prevention, access control, incident investigation, troubleshooting and maintenance)

6) Legal bases

We rely on the following legal bases under the GDPR, depending on the context:

Legitimate interest: Organization of training sessions and assessment of knowledge and training. Administration and securing of the Application.

Performance of a contract: Management of training requests and training periods completed.

7) Recipients of personal data

Internal recipients (authorized persons only):

Human Resources (HR) and training teams

Managers/line managers (to the extent necessary for training management)

IT and security teams (support, security, incident management)

External recipients (processors):

Service providers involved in the development, hosting, maintenance, and support of the Application

All recipients are subject to appropriate
confidentiality and data protection obligations.

8) International data transfers

Certain recipients may be located in, or access data from, foreign countries, particularly outside the EU. When international transfers take place, they are framed by appropriate safeguards in accordance with applicable law.

9) Retention periods

We retain personal data:

For the duration of the employment relationship, then

Archived for 5 years.

10) Security

We implement appropriate technical and organizational measures to protect personal data, notably access controls, role-based authorizations, authentication, logging/supervision, secure hosting, and encryption in transit.

11) Your rights

Subject to their admissibility, you have the following rights:

Right of access;

Right to rectification;

Right to erasure;

Right to restriction of processing;

Right to object.

12) Complaints

In case of questions regarding the processing of your personal data, you can contact our Data Protection Officer at the following address: privacy@chaumet.com. You also have the right to lodge a complaint with the competent supervisory authority (e.g., in France, the CNIL).

13) Cookies

The Application may use cookies or similar technologies strictly necessary for authentication, session management, and security.

14) Updates to the notice

We may update this information notice. The most recent version will be available within the Application.