PRIVACY POLICY
1. SCOPE OF THIS PRIVACY POLICY
The purpose of this privacy policy (hereinafter the “Policy“) is to explain how and why the personal data of a Client (“Client”, “you” and” your”), whose data is collected and processed by a certified Tomatis Practitioner to generate a Tomatis program in the Tomatis Studio Platform (hereinafter the “Platform“).
TOMATIS DEVELOPPEMENT SA is a Société Anonyme with a capital of 266 800 Euros, registered in Luxembourg under the RC number B 76 636 14 and whose registered office is located at L-1325 Luxembourg - 99137 (hereinafter” TOMATIS “,” we “,” us “,” our “and” our”) and act as a data processor.
Tomatis acts as a joint data controller with your Tomatis® Certified Practitioner.
2. Definitions
This document can be complex to read, which is why we have provided a few definitions to help you better understand the terms used below.
When these terms are used in the document, we write them in bold with a capital letter.
- Recipient: a legal or natural person who has access to Personal Data, or who receives it from the Data Controller.
- Personal Data: any information enabling the direct or indirect identification of a natural person, such as name, address, telephone number, e-mail address, etc.
- Data subject: a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more elements specific to their physical, physiological, genetic, psychological, economic, cultural or social identity
- Applicable regulations: set of texts relating to the protection of Personal Data, notably composed of European Regulation (EU) No. 2016-679 of April 27, 2016 relating to the protection of individuals with regard to the processing of personal data and the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation), the legislation applicable in your country.
- Data controller: the natural or legal person who determines the purposes and means of the processing of personal data. The concept of purpose refers to the objectives of the processing, and the concept of means refers to the way in which it is achieved (data to be used, conditions of collection, persons concerned by the processing, etc.).
- Subcontractor: the natural or legal person who implements the Processing of Personal Data on behalf of a Data Controller and on the basis of the latter’s instructions.
- Processing of personal data: any use of Personal Data. This concept covers a large number of activities such as collection, recording, organization, structuring, storage, adaptation, modification, extraction, consultation.
3. Purposes and legal bases for the processing of personal data
TOMATIS and your certified Tomatis Practitioner collect and process your Personal data to implement Processing having the purposes and legal bases referenced in table below:
Processing’s purposes
Management of the patient’s account and user profil
Sending the questionnaire to the patient
Analysis of the questionnaire result
Questionnaire for checking incompatibility with the Tomatis method
Downloading the program to the headset
Testing the patient’s hearing sensitivity
Creation of a programme tailored to the patient's needs
patient program management and monitoring
After-sales service and customer assistance
Legal Basis
legitimate interest of TOMATIS and your practicing professional to monitor and manage your profile
Pre-contractual measures taken at your request
Your consent
Your consent
Your consent
Your consent
Your consent
Your consent
Contractual measures
Management of requests to exercise data subjects’ rights Legal obligation arising from Article 12 of the GDPR
TOMATIS and your practicing professional do not reuse Personal Data for purposes other than those previously described. In particular, we want to emphasize that we do not carry out any automated decision-making operations.
4. Recipients of Personal Data
TOMATIS and your certified Tomatis Practitioner do not sell the Personal Data they collect and process in connection with the use of its website to third-party entities. However, the following third parties have access to your Personal Data:
Recipient
Audaxis (Avenue de l’Artisanat, 2 1420 Braine-l’Alleud - Belgium)
Amazon Web Services Europe
Explication of such data access
Web Developement services
Web Server Hosting services in Europe
We hereby inform you that we have taken the appropriate measures to ensure that they process your Personal Data in accordance with the applicable Regulations. These measures include entering into a contract with our subcontractors in order to govern our relationship in a manner consistent with such Applicable Regulations
5. Transfers outside the European Union
We will not transfer your data outside the European Union. We may do so if you and your practicing professional are abroad. In this case, we will have no choice but to allow your practicing professional access to your data.
6. Personal Data Retention
We may retain the Personal Data we collect and process for the following maximum periods. Processing’s
Management of the patient’s account and user profil
Sending the questionnaire to the patient
Analysis of the questionnaire result
Questionnaire for checking incompatibility with the Tomatis method
Up to the end of the consultation with the practicing professional, extended by 10 years
Up to the end of the consultation with the practicing professional, extended by 10 years
Up to the end of the consultation with the practicing professional, extended by 10 years
Up to the end of the consultation with the practicing professional, extended by 10 years
Downloading the program to the headset
Testing the patient’s hearing sensitivity
Creation of a programme tailored to the patient's needs
patient program management and monitoring
Up to the end of the consultation with the practicing professional, extended by 10 years
Up to the end of the consultation with the practicing professional, extended by 10 years
Up to the end of the consultation with the practicing professional, extended by 10 years
Up to the end of the consultation with the practicing professional, extended by 10 years
After-sales service and customer assistance 5 years
Management of requests to exercise data subjects’ rights 1 year after the exercise of the right
7. Your rights
In accordance with the applicable Regulations, you have the right to withdraw your consent at any time when it has been previously provided.
You also have the rights to access your Personal Data, request its deletion or correction, and the right to data portability. Additionally, you have the right to restrict the processing of your Personal Data and to object to such processing. Finally, you have the right to establish general or specific instructions regarding the handling of your Personal Data after your death.
Below, you will find a table summarizing the details of each of these rights to help you better understand them:
Your rights
Access right
The Right to Rectification
The Right to Erasure (the "Right to be Forgotten")
What does this mean?
You have the right to request access to your data and obtain a copy
You have the right to request the correction of your Personal Data if it is inaccurate or incomplete.
You have the right to request the deletion of your Personal Data. However, the right to erasure (or the "right to be forgotten") is not absolute and is subject to specific conditions. We may retain your Personal Data to the extent permitted by applicable regulations, particularly when processing remains necessary to comply with a legal obligation to which Tomatis and your practice professional is subject or for the establishment, exercise, or defence of legal claims.
The Right to Restriction of Processing
The Right to Data Portability
The Right to Object to Processing
The Right to Withdraw Consent
The Right to Define General or Specific Instructions Regarding the Use of Data After Death
You have the right to request the restriction of the processing of your Personal Data in certain circumstances (e.g., when TOMATIS or your practice professional no longer needs your Personal Data, but it is still required for the establishment, exercise, or defense of legal claims).
In certain circumstances, you have the right to receive your Personal Data that you have provided, in a structured, commonly used, and machine-readable format, and to transmit it to another data controller.
You have the right to object to certain types of processing (e.g., when the processing is based on the legitimate interests of TOMATIS or your practice professional).
If you have provided your consent for DOCTORS IN FRANCE to process your Personal Data, you have the right to withdraw it at any time.
You may define instructions regarding the retention, deletion, and disclosure of your Personal Data after your death. These instructions may be general or specific. General instructions are registered with a trusted third party, while specific instructions are submitted to each data controller.
These rights have specific conditions for their implementation depending on the context of the Personal Data processing activities. To exercise them, you may send us a written request at the following addresses, providing proof of your identity by any means:
By email, to the address privacy@tomatis.com, with the subject line "Personal Data Protection";
By postal mail, to the address: TOMATIS DEVELOPMENT 76 avenue de la Liberté, L 1930 Luxembourg., with the mention "Personal Data Protection".
If we are unable to verify your identity, we may ask you to provide additional information in this regard. We will inform you of any action taken in response to your request, which we will endeavour to process no later than one month from the date of its receipt.
You also have the right to file a complaint with the Commission nationale pour la protection des données (CNPD) if you believe we are not respecting your rights.
8. Updates to the Privacy Policy
We may update the Privacy Policy from time to time to reflect changes in our activities or in applicable regulations. The latest version of the Privacy Policy is the one available on our website : www.tomatis.com
Luxembourg, the 9th of December 2024
Version 1.0