PRIVACY NOTICE 


Publication/last update date: 01 January 2022
This privacy notice (the "Privacy Notice") applies to all processing of personal data (the "Personal Data") implemented in the context of the access to the services (the "Services") via the following applications (hereafter individually and collectively referred to as the "Application") :
For the purpose of this Privacy Notice, the term "Applicable Data Protection Regulation" means the European regulation no. 2016/679 of 27 April 2016 (the "General Data Protection Regulation" or "GDPR") as well as:
- with respect to the processing carried out by LEGRAND FRANCE, the French law no. 78-17 of 6 January 1978 and its application decree no. 2019-536 of 29 May 2019 (the "French Data Protection Legislation");
- with respect to processing carried out by BTICINO Spa, the Italian Legislative Decree no. 196 of 30 June 2003 (the "Italian Data Protection Code").

Any reference to the Applicable Data Protection Regulation shall be deemed to include any subsequent replacement of or amendment to the Applicable Data Protection Regulation (or part of the same).

IDENTITY OF THE DATA CONTROLLERS

The processing of Personal Data described in this Privacy Notice are implemented under the joint responsibility of the following companies belonging to the LEGRAND group ("LEGRAND" or "we" (and its derivatives)):

LEGRAND FRANCE
128, avenue du Maréchal de Lattre de Tassigny
87045 Limoges Cedex (France)

BTICINO Spa (or "BTICINO")
Viale Borri 231
21100 VARESE (Italy)

For more information about the allocation of roles between LEGRAND FRANCE, and BTICINO Spa regarding the processing of your Personal Data, you can obtain the key points of the arrangement between LEGRAND FRANCE, and BTICINO and on request regarding the concerned processing, by contacting us using the contact information provided in the "CONTACT US & CONTACT OUR DPO" section.

ACCOUNT CREATION

To benefit from our offer (e.g. to use the Application), you need to be registered by creating a personal account (the “Account”).
When creating the Account, you will be asked to enter an email address and a password (hashed). Please note that these log-in details are both required and necessary to provide the Services that you are requesting. If a mandatory field is not filled in, your Account cannot be created and you will not be able to benefit from the Services / Products.

COLLECTED DATA, PURPOSES OF THE PROCESSING AND LEGAL BASIS

The Personal Data that you provide to us


Type of Personal Data
Purposes of the processing
Legal basis
Email address*
Password*
Name*
Surname*
Country*
Address

Creation and management of your Account

Performance of the contract based on the general terms of use of the Application**


Sending communications , surveys and/or quizzes in connection with your Application, Products and/or Services
Our legitimate interest in continuously developing and improving our Products, Services and customer relations


Direct marketing and customized business development based on analytical profiling (if any)
We will process your email address in order to send you offers, new Products/Services, news and promotions relating to Products offered by the LEGRAND group companies: LEGRAND FRANCE, NETATMO and BTICINO

Your consent
Areas of interest identified from the Products used and/or purchased
Analytical profiling in order to customize our business communications
We can send you communications , surveys and/or quizzes in connection with your Application, Products and/or Services

Our legitimate interest in the ongoing improvement of our communications and customer relations
Plant name
Plant address
Plant configuration
(serial number of the installed device, addresses, etc.)*
Configuration of the installation and customization of the user experience
Performance of the contract based on the general terms of use of the Application**
Last name, first name, email address, request to exercise the rights, expression of consent, withdrawal of consent, opposition request, request to unsubscribe from business communications
Notifications done pursuant to the General terms of use of the Application
Performance of the contract based on the general terms of use of the Application**
Processing of your requests to exercise your rights

Management of consent and withdrawal of consent, management of opposition requests against business prospections and profiling

Sending of information regarding changes made to the Privacy Notice

Compliance with our obligations resulting from the Applicable Data Protection Regulation
*The collection and processing of these Personal Data are mandatory and necessary for the creation of your Account and allow access to the relevant Service.
**The general terms of use of the Application are available here https://www.myhomeweb.com/eliot/legacy/gdpr_contract_agreement_en_US.html

The Personal Data collected when you use the Application, the Services and/or the Products



Type of Personal Data
Purposes of the processing
Legal basis
Bticino Thermostat and Legrand Thermostat: Location (GPS) of the plant upon first installation
Registration of the Product(s)
Identification of the available Wi-Fi networks for the installation of the Product
Performance of the contract based on the general terms of use of the Application*
Language and country of the the smarthphone
Customization of the language on your Application

Performance of the contract based on the general terms of use of the Application*
- State (network connectivity, etc.)

- Temperature profile programmes (by user and by device) and instantaneous temperature of the smart Thermostat (temperature)

- For Connected Door Entry Products: events from external panel (as calls and connection status), Locks.
- Technical logs, sent only on voluntary basis: data/protocols managed/exchanged by applications and devices in order to perform the designed functionalities

- details as software and hardware versions, models, devices addresses, friendly name, etc.

Delivery of the relevant Services

Technical support
Performance of the contract based on the general terms of use of the Application*
- State (network connectivity, etc.)

- Temperature profile programs (by user and by device) and instantaneous temperature of the smart Thermostat (temperature)

- For Connected Door Entry Products: events from external panel (as calls and connection status), Locks.
- Technical logs, sent only on voluntary basis: data/protocols managed/exchanged by applications and devices in order to perform the designed functionalities

- details as software and hardware versions, models, devices addresses, friendly name, etc.

R&D analysis in order to improve the content and functionalities of our Products and Services

Our legitimate interest in the ongoing improvement of our Products and Services

Type of equipment and name(s) of the Products, etc.
Configuration of the installation and customization of the user experience

Performance of the contract based on the general terms of use of the Application*
Type of equipment and name(s) of the Products, etc.
Analytical profiling in order to send more relevant communications with respect to the purchased Products
Our legitimate interest in the ongoing improvement of our communications and customer relations
-Date and time of configuration / installation /Date and time of last connection of each Product

Technical support

Performance of the contract based on the general terms of use of the Application*
Date and time of last connection of user
Identification and deletion of inactive user account
Our legitimate interest to avoid maintaining inactive user account

Technical Personal Data: IP address and MAC Address of the connected device, Public IP address of the network, type of mobile device and mobile device model

Product registration

Provision of the Services

Maintenance of the Products

Technical support

Performance of the contract based on the general terms of use of the Application*
Language selected for the device, Products used and/or purchased
Push notifications and/or Communications in your Application for operational / technical purposes
(subject to choices you have made)
Performance of the contract based on the general terms of use of the Application*
Language selected for the device, Products used and/or purchased
Communications in your Application for business purposes
Legitimate interest in drawing your attention to our Products and Services and in the ongoing improvement of our communications
Audience analysis data
Evaluation of the effectiveness of our business campaigns. To learn more about this processing, please see the "COOKIES AND SIMILAR TECHNOLOGIES" section below.
Your consent

*The general terms of use of the Application are available here https://www.myhomeweb.com/eliot/legacy/gdpr_contract_agreement_en_US.html .

Balancing of legitimate interests

When we indicate in the Privacy Notice that we are relying on our legitimate interests to process your Personal Data, this means that we consider that our legitimate interests are not overridden by your interests or fundamental rights and freedoms, in light of the circumstances and measures that we take to protect your privacy. You can obtain more information about this analysis (the "Balancing test") on request, by contacting us using the contact information provided in the "CONTACT US & CONTACT OUR DPO" section.

RECIPIENTS HAVING ACCESS TO THE DATA

Only the following recipients will have access to your Personal Data, within the limits set out below:
- The Research and Development (R&D) teams responsible for the Application have access to: the Personal Data of your Account (email address only), the Personal Data relating to measurement collected through the Products and the Personal Data collected by third-party cookies and services necessary for the proper performance of the Application and audience measurements (see the COOKIES AND SIMILAR TECHNOLOGIES section for further details);
- The marketing teams, responsible for direct marketing and business prospecting operations, have access, where relevant, to: the Personal Data of your Account (email address and Products only);
- The teams from our customer service department have access to: the Personal Data of your Account (email address only), the Personal Data collected as part of the use of the Products for support purposes when you request it and the history of your conversations with our customer service department.
- IT Department, responsible for the correct service delivery
- The administrators of LEGRAND's cloud which hosts all of your Personal Data;





You are hereby informed that the aforementioned recipients of Personal Data are subject to a confidentiality obligation and have undertaken to use your Personal Data in accordance with our contractual arrangements and the Applicable Data Protection Regulation. Where your Personal Data are transferred outside the European Economic Area ("EEA"), we have notably put in place security and confidentiality safeguards that are deemed appropriate in the light of the GDPR. For your information, you may obtain access to these safeguards, on request, by contacting us at the address indicated in the "CONTACT US & CONTACT OUR DPO" section.
You may decide to invite one or several other users to use the Products from your Account. To that end, those users will be required to create their own personal accounts.

DATA RETENTION PERIODS

We process your Personal Data for the following durations:

Purpose of the processing
Retention duration of the Personal Data

  • Commercial prospecting and direct marketing activities via email or directly on the Application
Term of our contractual relationship, which ends by using the functionality in the app or by sending LEGRAND a request to delete the Account and the related data (see "CONTACT US & CONTACT OUR DPO" section) or your Account will be deleted if it remains inactive for three (3) consecutive years since its last use, unless you object to this deletion.
  • Notifications or alerts on your Application
Term of our contractual relationship, which ends by using the functionality in the app or by sending LEGRAND a request to delete the Account and the related data (see "CONTACT US & CONTACT OUR DPO" section) or your Account will be deleted if it remains inactive for three (3) consecutive years since its last use, unless you object to this deletion.
  • Analytical profiling in order to customize our business communications, from the Products used and/or purchased by you
Term of our contractual relationship, which ends by using the functionality in the app or by sending LEGRAND a request to delete the Account and the related data (see "CONTACT US & CONTACT OUR DPO" section) or your Account will be deleted if it remains inactive for three (3) consecutive years since its last use, unless you object to this deletion.
  • Language selected for the device in order to adapt the content of our communications
Term of our contractual relationship, which ends by using the functionality in the app or by sending LEGRAND a request to delete the Account and the related data (see "CONTACT US & CONTACT OUR DPO" section) or your Account will be deleted if it remains inactive for three (3) consecutive years since its last use, unless you object to this deletion.
  • Evaluation of the effectiveness of our business campaigns using audience measurement tools installed in the Application
Google Analytics: thirteen (13) months as from the date on which the measurement tool is placed in the Application
  • Technical analysis of the functioning of Products and Applications to study anomalies and to correct them (concerns data sent on a voluntary basis by the user when he requests for technical support)
Twenty four (24) months as from the date of your request

Account management and configuration of the Application:
  • Creation and management of your Account, conditioning your access to our Services
  • Configuration of the installation and customization of your user experience
  • Creation of your customer card on the LEGRAND customer management tool (Salesforce)
Term of our contractual relationship, which ends either (i) by sending LEGRAND a request to delete the Account and the related data (see "CONTACT US & CONTACT OUR DPO" section).

Processing of the Personal Data collected when you use the Application, the Services and/or the Products:
  • Registration of the Products, provision of the Services, Maintenance of the Products
  • Identification of the available Wi-Fi networks
  • Measurements data collected by the Products as defined above
  • Customization of the language on your Application
  • Customization of the information applicable to your geographical area
  • R&D analysis in order to improve the content and functionalities of our Products and Services
  • Configuration of the installation and customization of the user experience
  • Technical support
  • Identification and deletion of an inactive Account


Term of our contractual relationship, which ends either (i) by sending LEGRAND a request to delete the Account and the related data (see "CONTACT US & CONTACT OUR DPO" section).





  • Processing of your requests to exercise your rights
  • Sending of information regarding changes made to the Privacy Notice
Three (3) consecutive years as from the receipt of the request regarding the exercise of your rights or the sending of information regarding changes made to the Privacy Notice

Please note that the above durations remain subject to mandatory data retention requirements that may apply to us and, where relevant for the establishment, exercise or defence of legal claims, to the applicable statutory limitation periods.

Lastly, we draw to your attention that uninstalling our Application does not automatically imply the deletion of your Personal Data. To do so, you must send a voluntary deletion request to LEGRAND (see "CONTACT US & CONTACT OUR DPO" section) or make a request to unsubscribe (in accordance with the https://www.myhomeweb.com/eliot/legacy/gdpr_contract_agreement_en_US.html ).

THIRD-PARTY SERVICES PARTNERS

You may have the opportunity to subscribe for services provided by third-party partners that result from the sharing of our APIs (for example services making it possible to make some functionalities available from another interface, etc.). When you decide to use these third-party services partners, you must grant a delegation for access to the Personal Data available on the LEGRAND cloud, since we do not make your Personal Data available to third-party services partner without your express consent. This subscription shall also be subject to acceptance of specific general terms of use from the third-party services partner. In this case, the user recognizes that LEGRAND does not possess and has no control over these third-party services partners and that it is not responsible for the processing of Personal Data implemented by these third-party services partners. For more information about how these third-party services partners process your Personal Data, we recommend that you refer to the concerned third-party services partner's privacy notice.

DATA SECURITY

We have implemented adequate physical, electronic and administrative protection security measures in accordance with applicable regulations to protect your Personal Data. However, we wish to draw users' attention to the potential risks regarding confidentiality of the Personal Data related to internet usage. In particular, users are responsible for putting in place or ensuring the existence of means securing their personal internet network, as well as for ensuring the proper configuration of the box connected to the internet access provider, and other wireless access means (e.g. WIFI, 4G, etc.).

USERS' RIGHTS

We intend to keep your Personal Data accurate, complete and up-to-date. In order to do so, you can visit the " ACCOUNT" section of your Application.

Pursuant to the Applicable Data Protection Regulation, you benefit from the following rights in relation to the processing of your Personal Data:


To exercise any of these rights, you may send your request at any time, using the contact information provided in the "CONTACT US & CONTACT OUR DPO" section of this Privacy Notice. Requests will be processed as long as you can validly prove your identity and the subject of your request is clearly identified. Requests will be processed promptly, and in any case within no more than one (1) month from receipt of the request. If needed, this period may be extended by two (2) months, depending on the complexity of the request and number of requests. In this case, we will inform you of the reasons for this extension. No payment will be required to exercise your rights, except in case of clearly unfounded or excessive request. In this case, we also reserve the right not to grant your request.

In addition to the rights described above, you may lodge a complaint at any time with a competent supervisory authority. For instance, under the GDPR, you may lodge such a complaint in the country in which you reside or work (if relevant) or where the alleged breach has occurred, if you feel that our processing of your Personal Data breaches the Applicable Data Protection Regulation. In France, the supervisory authority is the Commission Nationale de l'Informatique et des Libertés (the"CNIL"). In Italy, the supervisory authority is the Garante per la Protezione dei Dati Personali (the"GPDP").

MINORS

In offering its information services (that is to say, the Application), LEGRAND does not target users that have not reached the legal age of majority applicable in their country.

However, access to the Application is not reserved for adults, since it does not include content prohibited to minors.

The Application does not intentionally collect or use personal information regarding minors. If information has been collected on a minor by LEGRAND, the legal representative of the minor may contact the Data Protection Officer at LEGRAND (using the contact information provided in the "CONTACT US & CONTACT OUR DPO" section) in order to, where relevant, correct, modify or delete this information or object to the processing of this information (refer to "USER'S RIGHTS" section).

MODIFICATION OF THE PRIVACY NOTICE

You can see the date of the last update to the Privacy Notice by referring to the "Last update" note at the top of the Privacy Notice.

When we are considering making substantial changes to this Privacy Notice (for example, a change to the processing purposes of the Personal Data, the identity of one or several data controllers, or the manner in which you can exercise your rights), you will be informed by the app and you have to accept it and renew your choices before continuing to use the app.
You are hereby informed that you can consult this Privacy Notice at any time in the “Accountà ACCOUNT INFORMATION”, which is accessible from your Application.

CONTACT US & CONTACT OUR DPO

By email:
Via the online form on the website

By mail:
Service Consommateurs Legrand
128, avenue du Maréchal de Lattre de Tassigny
87045 Limoges Cedex - France

Our DPO:
Data Protection Officer – Julie Celma
128, avenue du Maréchal de Lattre de Tassigny
87045 Limoges Cedex – France
fr-sm-data-protection-officer@legrand.com