Ir al contenido principal
Parousia Group

Legal

Política de privacidad

Privacy policy

Every processing operation this site performs, the legal basis for each, who receives the data, how long it is kept, and how to exercise your rights.

Idiomas que dan feEste documento hace fe en inglés y en francés. Aquí se muestra en inglés porque todavía no existe una versión revisada en este idioma: una traducción automática de un texto con efectos jurídicos sería peor que este aviso.

Who is responsible

The controller for the processing described in this policy is Parousia Group, entered in the trade and personal property credit register of Kinshasa/Gombe under number RCCM CD/KNG/RCCM/21-B-02650, whose registered office is at 157, avenue du Livre, Quartier Révolution, Commune de la Gombe, Kinshasa, Democratic Republic of the Congo. The company can be reached at contact@parousiagroup.com and on +243 892 844 000. Its national identification number and its tax number are published in the legal notice.

The group operates regional companies which handle the enquiries and the applications of their own market: Parousia West Africa (Lagos, Nigeria), Parousia East Africa (Nairobi, Kenya), Parousia Europe (London, United Kingdom), Parousia America Inc. (New York, United States), Parousia Middle East (Dubai, United Arab Emirates) and Echad Technologies (Singapore). Where a message is handled by one of them, that company is named in the reply you receive. Parousia Group remains the controller for the processing described here, and each regional company is bound by the same instructions.

Data Protection OfficeRequests relating to personal data are received and handled by the Data Protection Office, at contact@parousiagroup.com or by post to Parousia Group, Data Protection Office, 157, avenue du Livre, Quartier Révolution, Commune de la Gombe, Kinshasa, Democratic Republic of the Congo. The Office registers each request, satisfies itself that it comes from the person concerned or from an agent authorised by that person, and answers within the periods set out in the section “Your rights”. It keeps the record of processing operations reproduced below, holds the list of transfers and of the safeguards applicable to each, and acts with the Legal Department on requests from public authorities and on personal data breaches.

What this policy covers

This policy covers www.parousiagroup.com and the regional sites operated on the same codebase: westafrica, eastafrica, europe, americas, middleeast and apac.parousiagroup.com. The processing operations described are identical on each of them, a single application serving them all under the configuration of the entity concerned.

It does not cover the products operated under the group’s six solutions — NetVox Intelligence, Global Technology Africa, Afrika Plaza, PAGEXPRESS, PAGPay and INTIC — nor their own websites. Those services process personal data under their own notices and, where a contract governs them, under that contract. A link leading out of this site leads out of the scope of this policy.

It applies to visitors, to people who write to the group through the contact form, to subscribers to the newsletter and to candidates for a published role. Relations governed by a contract are also subject to that contract and, where the group acts as a processor for a client, to the data processing agreement concluded under Article 28 of the GDPR.

What is collected, and what is not

This site collects what you enter in one of its three forms, one language code, and the technical data of the requests it serves. There is no account to create and no login, and nothing is collected from you for reading a page beyond what the server records to serve and secure the request.

  • Contact form — first and last name, email address, and where you provide them telephone number, organisation and subject, together with the text of your message and the language of the interface.
  • Newsletter form — the email address and the language of the interface, and nothing else.
  • Application form — first and last name, email address, telephone number, location, the links you provide, your covering text, your CV file, the role applied for and the language of the interface.
  • Language cookie — the NEXT_LOCALE cookie holds a two-letter language code and no identifier. It is described in full in the cookie policy.
  • Server logs — the technical data of a request: IP address, date and time, address requested, HTTP status and the identification string sent by your browser.

No advertising network, third-party audience measurement tool or social network pixel is installed on this site. No special category of data within the meaning of Article 9 of the GDPR is requested; a CV may contain such data where its author has chosen to include it, and the group does not use it as a selection criterion. Personal data is collected from you and from no other source: the site receives nothing from a data broker, an advertising network or a social platform.

Record of processing operations

The table below is the record of the processing operations carried out by this site, kept under Article 30 of the GDPR. It states, for each operation, the purpose pursued, the categories of data processed, the legal basis, the categories of recipient and the retention period. It is exhaustive: a purpose that does not appear in it is not pursued on this site.

Processing operations carried out by this site (GDPR Article 30)
PurposeCategories of dataLegal basisRecipientsRetention
Answering a message sent through the contact formFirst and last name, email address; telephone number, organisation and subject where given; the text of the message; the language of the interfaceArt. 6(1)(f) GDPR — legitimate interest in answering an enquiry addressed to the group; Art. 6(1)(b) where the enquiry concerns a contract in prospectThe department of the group concerned by the enquiry; the regional company covering that market; the messaging or customer relationship management system that routes the message, as processor24 months from the last exchange
Sending the group newsletterEmail address; the language of the interfaceArt. 6(1)(a) GDPR — consent, which may be withdrawn at any timeThe Group Secretariat; the mailing system used to send the newsletter, as processorUntil you unsubscribe, and deleted within 30 days of the request
Assessing an application for a published roleFirst and last name, email address, telephone number, location, the links provided, the covering text, the CV file, the role applied for, the language of the interfaceArt. 6(1)(b) GDPR — steps taken at your request before entering into a contract of employmentHuman Resources; the regional company operating the role; the recruitment system that receives the application, as processorUntil recruitment for that role is closed, then 12 months
Serving and securing the site, and preventing abusive use of the formsIP address, date and time of the request, address requested, HTTP status, browser identification string; a submission counter held per IP address in the memory of the server processArt. 6(1)(f) GDPR — legitimate interest in the availability and the security of the site and in keeping the forms usableGroup Security and the department operating the site; the hosting provider, as processorServer logs: 12 months at most. Counter: one hour at most, held in memory, never written to disk and lost when the process restarts
Serving the site in the language chosenThe NEXT_LOCALE cookie: a two-letter language code, and nothing else. No identifierArt. 5(3) of the ePrivacy Directive — storage strictly necessary to provide the service you requested; Art. 6(1)(f) GDPR for the associated processingNo one. The value stays between your browser and this site12 months, or until you delete the cookie

The record is kept by the Data Protection Office, which enters a new operation in it before that operation begins and records the date of each amendment. A copy of the record as it applies to this site is sent on request to contact@parousiagroup.com, and it is produced to a supervisory authority under Article 30(4) of the GDPR.

Automated decisions

No decision producing legal effects concerning you or similarly significantly affecting you is taken solely on the basis of automated processing, including profiling, within the meaning of Article 22(1) of the GDPR. No message, subscription or application is accepted, ranked, scored or rejected by an automated process. An application is read by Human Resources with the department concerned, and the decision on it is taken by those persons.

No profiling within the meaning of Article 4(4) of the GDPR is carried out, and visitors, subscribers and candidates are not scored. Two automated checks do run, and neither decides anything about a person: a honeypot field which discards submissions made by robots, and the rate limit entered in the record. A submission stopped by either is refused with an explicit error and may be sent again, or addressed to contact@parousiagroup.com or careers@parousiagroup.com.

Who receives the data

The categories of recipient are those set out below, as required by Article 13(1)(e) of the GDPR. Personal data collected through this site is disclosed to no recipient outside this table.

Categories of recipient (GDPR Article 13(1)(e))
RecipientWhat it receivesCapacity
Parousia Group, KinshasaEvery submission made through this siteController
The regional company concerned — Lagos, Nairobi, London, New York, Dubai, SingaporeThe submissions its market handlesRecipient within the group, bound by the same instructions
The messaging, customer relationship management or recruitment systemThe fields of the form concerned, and the CV file for an applicationProcessor, under a contract meeting Article 28 of the GDPR
The hosting provider of the siteThe technical data needed to route and serve a request, and the server logsProcessor, under a contract meeting Article 28 of the GDPR
A public authority or a courtOnly what a binding legal request requires, after the Legal Department has verified that the request is bindingThird party, on a legal obligation

A processor is engaged only under a written contract meeting Article 28(3) of the GDPR: it processes personal data on documented instructions only, binds the persons it authorises to confidentiality, applies the security measures required by Article 32, engages a sub-processor only with the group’s prior written authorisation, assists the group with requests from data subjects and with breach notification, and deletes or returns the data at the end of the service. The Legal Department reviews that contract and the Data Protection Office approves the processing before the first record is transferred.

A request from a public authority is directed to the Legal Department, which verifies the authority of the requesting body, the legal basis invoked and the scope of what is sought, discloses only what the request requires, and informs the person concerned where the law allows it to do so.

Transfers outside your country

The group has its head office in the Democratic Republic of the Congo and companies in Nigeria, Kenya, the United Kingdom, the United States, the United Arab Emirates and Singapore. A message or an application sent from the European Economic Area is therefore likely to be read outside it.

Where the European Commission has adopted an adequacy decision under Article 45 of the GDPR covering the destination, the group relies on it. Where it has not — and no adequacy decision covers the Democratic Republic of the Congo — the transfer rests on the standard contractual clauses of Commission Implementing Decision (EU) 2021/914, supplemented, where the assessment required by the judgment in Case C-311/18 shows it to be necessary, by additional measures. Transfers from the United Kingdom rest on the International Data Transfer Agreement or on the UK Addendum to those clauses. The derogations of Article 49 are not used as a standing basis for routine transfers.

The same movement of data is subject, in the other jurisdictions, to their own cross-border rules: the transfer provisions of the Nigeria Data Protection Act 2023, those of the Kenya Data Protection Act, 2019, those of the Democratic Republic of the Congo’s code du numérique, Article 22 and following of UAE Federal Decree-Law No. 45 of 2021, and the transfer limitation obligation of Singapore’s Personal Data Protection Act 2012. The Data Protection Office holds the list of transfers and of the safeguard relied on for each, and the Legal Department concludes the instrument before the transfer begins.

Obtaining a copy of the safeguardsArticle 13(1)(f) of the GDPR gives you the right to obtain a copy of the safeguards relied on for a transfer. Write to contact@parousiagroup.com and the Data Protection Office will send you the clauses applicable to the transfer that concerns you, with commercial terms redacted. Redaction is limited to price and to terms that do not bear on the protection of the data.

How long data is kept

The retention periods are those set out in the record above. They are fixed by this policy, applied by the group and imposed on its processors by the contract concluded under Article 28 of the GDPR. Each period runs from the event named in the record — the last exchange, the unsubscribe request, the close of a recruitment, the date of the request served.

When a period expires the record is deleted; it is neither archived nor reduced to a form on which the group could still act. Where a processor holds a copy, the instruction to delete is passed to that processor and its execution is verified. Where a law to which the group is subject imposes a longer period — an accounting rule or a rule of limitation — only what that law requires is kept, and only for as long as it requires.

The Data Protection Office verifies the application of these periods and issues the instructions to delete. A request for erasure made before a period expires is handled under the section “Your rights”, and is granted where one of the grounds in Article 17 of the GDPR applies.

Security of the processing

Article 32 of the GDPR requires technical and organisational measures appropriate to the risk. Group Security defines the measures applied to this site, and the Data Protection Office verifies that they cover the processing operations entered in the record.

  • Every submission is validated again on the server. Validation performed by the browser is a convenience and is not treated as a guarantee.
  • No personal data is written to the application logs. The three form routes record the outcome of a submission and, for an application, the role applied for — never a name, an address, a message or a file name.
  • A CV is accepted only if its first bytes match the format it declares: PDF, the ZIP container of a DOCX or an ODT, or the OLE2 container of a legacy DOC. Its size is capped at 5 MB. The check bears on the format and is not a virus scan.
  • The file name sent with a CV is stripped of path separators and of characters that a downstream system could interpret.
  • The forms are rate limited by IP address, as entered in the record.
  • Transport is encrypted and pinned by a two-year HTTP Strict Transport Security policy with preload. The content security policy allows scripts, styles, images, fonts and connections from this origin only; framing is denied outright; the permissions policy denies camera, microphone, geolocation and interest-cohort access.
  • The site ships no third-party JavaScript, loads no remote image and no remote font, and calls no external mapping or font service. The office map is drawn from data held in the site itself.
  • Access to a submission is limited to the members of the department concerned who need it to answer, and each regional company is bound by the same instructions.

Where a personal data breach occurs and is likely to result in a risk to the rights and freedoms of the people concerned, the Data Protection Office, with Group Security, notifies the competent supervisory authority within 72 hours under Article 33 of the GDPR and informs the people concerned directly where Article 34 requires it. Every breach, whether or not it is notified, is entered in the record kept under Article 33(5). The equivalent notification duties of the Nigerian, Kenyan, Congolese, Emirati and Singaporean laws are met in the same movement.

Your rights

The rights below are those of Regulation (EU) 2016/679 and of the UK GDPR. Each is stated with the provision that founds it and the period within which the group answers.

  • Access — obtain confirmation that data concerning you is processed, a copy of that data, and the information in this policy applied to your own case (Art. 15; answered within one month).
  • Rectification — have inaccurate data corrected and incomplete data completed (Art. 16; answered within one month, and the correction is passed to every recipient of the data).
  • Erasure — have data deleted where one of the grounds in Article 17 applies, in particular where you withdraw the consent on which the processing rests or where the retention period has expired (Art. 17; answered within one month).
  • Restriction — have processing frozen while a challenge to the accuracy of the data or to a legitimate interest is determined (Art. 18; answered within one month, and you are informed before the restriction is lifted).
  • Portability — receive the data you provided, in a structured, commonly used and machine-readable format, and have it transmitted to another controller where that is technically feasible (Art. 20; answered within one month).
  • Objection — object at any time, on grounds relating to your particular situation, to processing based on legitimate interest (Art. 21; answered within one month, and the processing stops unless the group demonstrates compelling legitimate grounds).
  • Withdrawal of consent — withdraw at any time, without giving a reason and as easily as consent was given (Art. 7(3); effective on receipt and no later than 30 days afterwards).
  • Not to be subject to a decision based solely on automated processing (Art. 22; no such decision is taken here, as the section “Automated decisions” states).
  • Complaint to a supervisory authority — lodge a complaint with the authority of your choice among those competent, without having to apply to the group first (Art. 77; the authorities are listed in the section “Complaining to an authority”).

The laws that apply to the group outside Europe grant rights of the same nature, and they are exercised by the same route and answered by the Data Protection Office.

  • Nigeria — Nigeria Data Protection Act 2023: rights to be informed, of access, of rectification, of erasure, of restriction, of portability, to object to processing and to withdraw consent. Complaints are made to the Nigeria Data Protection Commission.
  • Kenya — Data Protection Act, 2019, section 26: rights to be informed of the use of the data, of access, to object to processing, to correction of false or misleading data, to deletion, and to portability. Complaints are made to the Office of the Data Protection Commissioner.
  • Democratic Republic of the Congo — ordonnance-loi n° 23/010 of 13 March 2023 (code du numérique) and loi n° 20/017 of 25 November 2020: rights to information, of access, of rectification, of deletion and to object, exercised with the group at its registered office in Kinshasa and before the authority designated by the code du numérique.
  • United Arab Emirates — Federal Decree-Law No. 45 of 2021, Articles 13 to 17: rights to obtain information about the processing, to data portability, to rectification or erasure, to restriction of processing and to object. Complaints are made to the UAE Data Office.
  • Singapore — Personal Data Protection Act 2012: right to withdraw consent (section 16), right of access (section 21) and right of correction (section 22). Complaints are made to the Personal Data Protection Commission.
  • California — California Consumer Privacy Act as amended by the CPRA: rights to know, to delete, to correct, to opt out of the sale or sharing of personal information, to limit the use of sensitive personal information and not to be discriminated against for exercising them (Cal. Civ. Code §§ 1798.100 to 1798.125), answered within 45 days and extendable once by a further 45 days (§ 1798.130). The section “Residents of California” sets out how they apply here.
How to exercise a right, and by when the group answersWrite to the Data Protection Office at contact@parousiagroup.com, or by post to 157, avenue du Livre, Quartier Révolution, Commune de la Gombe, Kinshasa, Democratic Republic of the Congo. State what you are asking for; you need not cite an article or use any particular wording. The group answers within one month and may extend that period by two further months where the request is complex or where several requests are made, in which case it informs you of the extension and of its reasons within the first month (Art. 12(3)). Answering is free of charge (Art. 12(5)). Where the group cannot identify you from the data it holds, it says so rather than collect identity documents to close the gap (Arts. 11 and 12(6)). A right may be exercised through an agent authorised in writing.

Complaining to an authority

You are not required to apply to the group first, and nothing in this policy limits that right. Article 77 of the GDPR, and the equivalent provisions of the other laws listed below, allow you to complain directly to the authority competent for your situation.

Supervisory authorities by jurisdiction
JurisdictionInstrumentAuthority
European Union and European Economic AreaRegulation (EU) 2016/679, Article 77The supervisory authority of your Member State of residence, of your place of work, or of the place of the alleged infringement
United KingdomUK GDPR; Data Protection Act 2018Information Commissioner’s Office (ICO)
Democratic Republic of the CongoOrdonnance-loi n° 23/010 du 13 mars 2023 (code du numérique); loi n° 20/017 du 25 novembre 2020The authority designated under the code du numérique
NigeriaNigeria Data Protection Act 2023Nigeria Data Protection Commission (NDPC)
KenyaData Protection Act, 2019Office of the Data Protection Commissioner (ODPC)
United Arab EmiratesFederal Decree-Law No. 45 of 2021UAE Data Office
SingaporePersonal Data Protection Act 2012Personal Data Protection Commission (PDPC)
CaliforniaCal. Civ. Code §§ 1798.100 et seq.California Privacy Protection Agency; California Attorney General

A complaint may also be addressed to the Data Protection Office at contact@parousiagroup.com, which answers within one month. Doing so neither suspends nor limits the right to apply to a supervisory authority, and it does not affect the judicial remedies available under Articles 78 and 79 of the GDPR.

Residents of California

This section is given under the California Consumer Privacy Act as amended by the CPRA. In the categories of Cal. Civ. Code § 1798.140(v), the site collects identifiers (name, email address, telephone number, IP address), professional or employment-related information (the content of an application and the CV attached to it), internet activity information limited to the server logs described in the record, and the content of the electronic communications you choose to send through the contact form. It collects no biometric information, no geolocation data, no government identifier and no financial account information.

Each category is collected from the consumer alone, for the purpose stated against it in the record above, disclosed only to the recipients listed in the section “Who receives the data”, and kept for the period stated in the record. No category is disclosed to a third party for that third party’s own commercial purposes.

No sale and no sharing of personal informationThe group does not sell personal information and does not share it for cross-context behavioural advertising, as those terms are defined in Cal. Civ. Code § 1798.140. It has not done so in the twelve months preceding the date of this document, and it does not sell or share the personal information of consumers it knows to be under 16. Cal. Civ. Code § 1798.135 requires an opt-out link only of a business that sells or shares personal information; none is displayed on this site. The rights to know, to delete, to correct, to limit the use of sensitive personal information and not to be discriminated against for exercising them are exercised by the route set out in the section “Your rights”, in person or through an authorised agent, and are answered within 45 days.

Children

These sites are addressed to institutions, clients, journalists and candidates for employment. They are not directed at children, no service offered here is an information society service offered directly to a child within the meaning of Article 8 of the GDPR, and the group does not knowingly collect data from a person below the age at which their country allows them to work.

Where the group learns that it holds data relating to such a person, the Data Protection Office deletes it. A parent or guardian who considers that a child has sent personal data through this site may write to contact@parousiagroup.com, and the data is deleted without the requester having to establish anything beyond the circumstances of the sending.

Changes to this policy

This document carries a version number, a review date and an effective date, and all three are displayed. A change that adds a purpose, a recipient, a transfer or a longer retention period raises the version number and is announced on the site before it takes effect. A correction of wording that changes nothing in substance raises the minor number only.

Earlier versions are kept by the Group Secretariat, and a copy of the version in force on a given date is sent on request to contact@parousiagroup.com. The Data Protection Office reviews this policy at least once a year and whenever a processing operation, a recipient or a retention period changes.

Base normativa

  • Regulation (EU) 2016/679 (GDPR) — Articles 4, 6, 9, 12 to 22, 28, 30, 32, 44 to 49 and 77
  • UK GDPR and Data Protection Act 2018 (c. 12)
  • Directive 2002/58/EC (ePrivacy) as amended by Directive 2009/136/EC — Article 5(3)
  • Commission Implementing Decision (EU) 2021/914 — standard contractual clauses
  • CJEU, 16 July 2020, Data Protection Commissioner v Facebook Ireland and Schrems, C-311/18
  • Nigeria Data Protection Act 2023
  • Kenya Data Protection Act, 2019 (No. 24 of 2019)
  • République démocratique du Congo — loi n° 20/017 du 25 novembre 2020 relative aux télécommunications et aux technologies de l’information et de la communication
  • République démocratique du Congo — ordonnance-loi n° 23/010 du 13 mars 2023 portant code du numérique
  • United Arab Emirates — Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
  • Singapore Personal Data Protection Act 2012 (No. 26 of 2012)
  • California Consumer Privacy Act as amended by the CPRA — Cal. Civ. Code §§ 1798.100 et seq.