Privacy policy

This policy describes the data collected by Pixeo Group through soriston.com and the Soriston platform, the purposes of processing and the rights available to you.

Updated on

Data controller

Pixeo Group, registered under SIREN 840 047 724, with its registered office at 66 avenue des Champs-Élysées, 75008 Paris, France. Contact: contact@pixeogroup.com.

Depending on the situation, Pixeo Group acts:

  • as data controller for data collected through its website, forms and commercial exchanges;
  • as processor under article 28 of the GDPR when Soriston is used on behalf of a client company, training provider or institution that determines the purposes.

Data collected through the website

When you complete a form or contact Pixeo Group, the following data may be collected:

  • first name and surname;
  • email address;
  • telephone number;
  • company or organisation name;
  • job title;
  • message content and information relating to your request.

Technical browsing data may also be processed to ensure the site operates correctly, remains secure and to measure audience.

Data collected within Soriston

Use of the Soriston platform may involve processing the following data:

  • identity: first name, surname, email address, telephone;
  • affiliation: company, training provider or institution;
  • profile picture, if the user chooses to add one;
  • preferred language;
  • usage history, modules taken, progress and time spent;
  • results, scores and answers given;
  • interactive elements selected, errors made, level of assistance used and reaction times.

This data allows learners to follow their own training, the relevant organisation to monitor team progress, and Pixeo Group to ensure the technical and educational operation of the platform.

Legal bases

  • performance of a contract or pre-contractual measures, for providing Soriston and handling requests;
  • legitimate interest, for site security, audience measurement and commercial relations;
  • consent, for marketing communications and non-essential cookies;
  • legal obligation, for retaining accounting and contractual records.

Authentication

Soriston users authenticate with a one-time code sent by email. No user password is required or stored.

Data stored on the device

Some features allow content to be downloaded for offline use. The videos and learning materials required may then be stored locally on the device.

Results produced offline are synchronised with Soriston servers once the connection is restored.

Permissions requested by the applications

Depending on the device, Soriston applications may request certain permissions, only where necessary for a specific feature.

Access to photos or the gallery may be requested to allow a profile picture to be added, and is used solely for that purpose. Soriston does not automatically collect photos, videos or personal files stored on the device.

Soriston does not require access to location, microphone or camera for normal operation. Users can manage permissions at any time from their device settings.

Recipients and processors

Data is accessible to authorised Pixeo Group staff, to the client organisation in respect of its own learners, and to technical providers involved in hosting, email delivery and maintenance. Those providers are bound by contractual confidentiality and security commitments.

Hosting and transfers

Data is hosted within the European Union. Any transfer outside the European Union would be governed by the appropriate safeguards provided for by the GDPR.

Retention periods

  • contact and demo requests: three years from the last exchange;
  • training data within Soriston: for the term of the contract, then three years unless a different period is agreed with the client organisation;
  • accounting and contractual records: ten years, in line with legal obligations;
  • trackers and audience measurement: thirteen months maximum.

Your rights

Under the GDPR you have rights of access, rectification, erasure, restriction, objection and portability, together with the right to set instructions regarding your data after your death.

These rights can be exercised at contact@pixeogroup.com. Where your account is managed by your employer or training provider, your request may be passed to that organisation, which determines the purposes of processing.

You may also lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, 75007 Paris.

Security

Pixeo Group implements appropriate technical and organisational measures to protect data against destruction, loss, alteration, unauthorised disclosure or access. These include encryption in transit, access rights management and access logging.

Changes to this policy

This policy may be updated to reflect legal, technical or functional changes. The date of the latest update appears at the top of this page.