
Legal
Política de privacidad
Privacy policy
Every processing operation this site performs, the legal basis for each, who receives the data, how long it is kept, and how to exercise your rights.
Who is responsible
The controller for the processing described in this policy is Parousia Group, entered in the trade and personal property credit register of Kinshasa/Gombe under number RCCM CD/KNG/RCCM/21-B-02650, whose registered office is at 157, avenue du Livre, Quartier Révolution, Commune de la Gombe, Kinshasa, Democratic Republic of the Congo. The company can be reached at contact@parousiagroup.com and on +243 892 844 000. Its national identification number and its tax number are published in the legal notice.
The group operates regional companies which handle the enquiries and the applications of their own market: Parousia West Africa (Lagos, Nigeria), Parousia East Africa (Nairobi, Kenya), Parousia Europe (London, United Kingdom), Parousia America Inc. (New York, United States), Parousia Middle East (Dubai, United Arab Emirates) and Echad Technologies (Singapore). Where a message is handled by one of them, that company is named in the reply you receive. Parousia Group remains the controller for the processing described here, and each regional company is bound by the same instructions.
What this policy covers
This policy covers www.parousiagroup.com and the regional sites operated on the same codebase: westafrica, eastafrica, europe, americas, middleeast and apac.parousiagroup.com. The processing operations described are identical on each of them, a single application serving them all under the configuration of the entity concerned.
It does not cover the products operated under the group’s six solutions — NetVox Intelligence, Global Technology Africa, Afrika Plaza, PAGEXPRESS, PAGPay and INTIC — nor their own websites. Those services process personal data under their own notices and, where a contract governs them, under that contract. A link leading out of this site leads out of the scope of this policy.
It applies to visitors, to people who write to the group through the contact form, to subscribers to the newsletter and to candidates for a published role. Relations governed by a contract are also subject to that contract and, where the group acts as a processor for a client, to the data processing agreement concluded under Article 28 of the GDPR.
What is collected, and what is not
This site collects what you enter in one of its three forms, one language code, and the technical data of the requests it serves. There is no account to create and no login, and nothing is collected from you for reading a page beyond what the server records to serve and secure the request.
- Contact form — first and last name, email address, and where you provide them telephone number, organisation and subject, together with the text of your message and the language of the interface.
- Newsletter form — the email address and the language of the interface, and nothing else.
- Application form — first and last name, email address, telephone number, location, the links you provide, your covering text, your CV file, the role applied for and the language of the interface.
- Language cookie — the NEXT_LOCALE cookie holds a two-letter language code and no identifier. It is described in full in the cookie policy.
- Server logs — the technical data of a request: IP address, date and time, address requested, HTTP status and the identification string sent by your browser.
No advertising network, third-party audience measurement tool or social network pixel is installed on this site. No special category of data within the meaning of Article 9 of the GDPR is requested; a CV may contain such data where its author has chosen to include it, and the group does not use it as a selection criterion. Personal data is collected from you and from no other source: the site receives nothing from a data broker, an advertising network or a social platform.
Record of processing operations
The table below is the record of the processing operations carried out by this site, kept under Article 30 of the GDPR. It states, for each operation, the purpose pursued, the categories of data processed, the legal basis, the categories of recipient and the retention period. It is exhaustive: a purpose that does not appear in it is not pursued on this site.
| Purpose | Categories of data | Legal basis | Recipients | Retention |
|---|---|---|---|---|
| Answering a message sent through the contact form | First and last name, email address; telephone number, organisation and subject where given; the text of the message; the language of the interface | Art. 6(1)(f) GDPR — legitimate interest in answering an enquiry addressed to the group; Art. 6(1)(b) where the enquiry concerns a contract in prospect | The department of the group concerned by the enquiry; the regional company covering that market; the messaging or customer relationship management system that routes the message, as processor | 24 months from the last exchange |
| Sending the group newsletter | Email address; the language of the interface | Art. 6(1)(a) GDPR — consent, which may be withdrawn at any time | The Group Secretariat; the mailing system used to send the newsletter, as processor | Until you unsubscribe, and deleted within 30 days of the request |
| Assessing an application for a published role | First and last name, email address, telephone number, location, the links provided, the covering text, the CV file, the role applied for, the language of the interface | Art. 6(1)(b) GDPR — steps taken at your request before entering into a contract of employment | Human Resources; the regional company operating the role; the recruitment system that receives the application, as processor | Until recruitment for that role is closed, then 12 months |
| Serving and securing the site, and preventing abusive use of the forms | IP address, date and time of the request, address requested, HTTP status, browser identification string; a submission counter held per IP address in the memory of the server process | Art. 6(1)(f) GDPR — legitimate interest in the availability and the security of the site and in keeping the forms usable | Group Security and the department operating the site; the hosting provider, as processor | Server logs: 12 months at most. Counter: one hour at most, held in memory, never written to disk and lost when the process restarts |
| Serving the site in the language chosen | The NEXT_LOCALE cookie: a two-letter language code, and nothing else. No identifier | Art. 5(3) of the ePrivacy Directive — storage strictly necessary to provide the service you requested; Art. 6(1)(f) GDPR for the associated processing | No one. The value stays between your browser and this site | 12 months, or until you delete the cookie |
The record is kept by the Data Protection Office, which enters a new operation in it before that operation begins and records the date of each amendment. A copy of the record as it applies to this site is sent on request to contact@parousiagroup.com, and it is produced to a supervisory authority under Article 30(4) of the GDPR.
Legal bases
Where the basis is consent — the newsletter — you may withdraw it at any time under Article 7(3) of the GDPR. Withdrawal is as easy as giving consent: one link in every newsletter, or one message to contact@parousiagroup.com. It takes effect on receipt and no later than 30 days afterwards, and it does not affect the lawfulness of the processing carried out before it.
Where the basis is legitimate interest, the interest pursued is stated in the record: answering a message addressed to the group, and keeping the site available, secure and usable. The group has weighed that interest against the rights and freedoms of the people concerned, and limits the processing to what those purposes require. You may object to it at any time, on grounds relating to your particular situation, under Article 21 of the GDPR.
Where the basis is the performance of steps taken before entering into a contract, it covers the assessment of an application for a published role. Where a law to which the group is subject requires it to keep or to disclose data, the basis is the legal obligation under Article 6(1)(c) of the GDPR, and only what that law requires is processed.
The same operations are carried out under the equivalent bases of the other laws that apply to the group: the lawful bases of the Nigeria Data Protection Act 2023, those of the Kenya Data Protection Act, 2019, the consent and legitimate purpose rules of the Democratic Republic of the Congo’s code du numérique, Article 4 of UAE Federal Decree-Law No. 45 of 2021, and the consent and deemed consent provisions of Singapore’s Personal Data Protection Act 2012. Where two laws set different requirements for the same operation, the group applies the stricter one.
Automated decisions
No decision producing legal effects concerning you or similarly significantly affecting you is taken solely on the basis of automated processing, including profiling, within the meaning of Article 22(1) of the GDPR. No message, subscription or application is accepted, ranked, scored or rejected by an automated process. An application is read by Human Resources with the department concerned, and the decision on it is taken by those persons.
No profiling within the meaning of Article 4(4) of the GDPR is carried out, and visitors, subscribers and candidates are not scored. Two automated checks do run, and neither decides anything about a person: a honeypot field which discards submissions made by robots, and the rate limit entered in the record. A submission stopped by either is refused with an explicit error and may be sent again, or addressed to contact@parousiagroup.com or careers@parousiagroup.com.
Who receives the data
The categories of recipient are those set out below, as required by Article 13(1)(e) of the GDPR. Personal data collected through this site is disclosed to no recipient outside this table.
| Recipient | What it receives | Capacity |
|---|---|---|
| Parousia Group, Kinshasa | Every submission made through this site | Controller |
| The regional company concerned — Lagos, Nairobi, London, New York, Dubai, Singapore | The submissions its market handles | Recipient within the group, bound by the same instructions |
| The messaging, customer relationship management or recruitment system | The fields of the form concerned, and the CV file for an application | Processor, under a contract meeting Article 28 of the GDPR |
| The hosting provider of the site | The technical data needed to route and serve a request, and the server logs | Processor, under a contract meeting Article 28 of the GDPR |
| A public authority or a court | Only what a binding legal request requires, after the Legal Department has verified that the request is binding | Third party, on a legal obligation |
A processor is engaged only under a written contract meeting Article 28(3) of the GDPR: it processes personal data on documented instructions only, binds the persons it authorises to confidentiality, applies the security measures required by Article 32, engages a sub-processor only with the group’s prior written authorisation, assists the group with requests from data subjects and with breach notification, and deletes or returns the data at the end of the service. The Legal Department reviews that contract and the Data Protection Office approves the processing before the first record is transferred.
A request from a public authority is directed to the Legal Department, which verifies the authority of the requesting body, the legal basis invoked and the scope of what is sought, discloses only what the request requires, and informs the person concerned where the law allows it to do so.
Transfers outside your country
The group has its head office in the Democratic Republic of the Congo and companies in Nigeria, Kenya, the United Kingdom, the United States, the United Arab Emirates and Singapore. A message or an application sent from the European Economic Area is therefore likely to be read outside it.
Where the European Commission has adopted an adequacy decision under Article 45 of the GDPR covering the destination, the group relies on it. Where it has not — and no adequacy decision covers the Democratic Republic of the Congo — the transfer rests on the standard contractual clauses of Commission Implementing Decision (EU) 2021/914, supplemented, where the assessment required by the judgment in Case C-311/18 shows it to be necessary, by additional measures. Transfers from the United Kingdom rest on the International Data Transfer Agreement or on the UK Addendum to those clauses. The derogations of Article 49 are not used as a standing basis for routine transfers.
The same movement of data is subject, in the other jurisdictions, to their own cross-border rules: the transfer provisions of the Nigeria Data Protection Act 2023, those of the Kenya Data Protection Act, 2019, those of the Democratic Republic of the Congo’s code du numérique, Article 22 and following of UAE Federal Decree-Law No. 45 of 2021, and the transfer limitation obligation of Singapore’s Personal Data Protection Act 2012. The Data Protection Office holds the list of transfers and of the safeguard relied on for each, and the Legal Department concludes the instrument before the transfer begins.
How long data is kept
The retention periods are those set out in the record above. They are fixed by this policy, applied by the group and imposed on its processors by the contract concluded under Article 28 of the GDPR. Each period runs from the event named in the record — the last exchange, the unsubscribe request, the close of a recruitment, the date of the request served.
When a period expires the record is deleted; it is neither archived nor reduced to a form on which the group could still act. Where a processor holds a copy, the instruction to delete is passed to that processor and its execution is verified. Where a law to which the group is subject imposes a longer period — an accounting rule or a rule of limitation — only what that law requires is kept, and only for as long as it requires.
The Data Protection Office verifies the application of these periods and issues the instructions to delete. A request for erasure made before a period expires is handled under the section “Your rights”, and is granted where one of the grounds in Article 17 of the GDPR applies.
Security of the processing
Article 32 of the GDPR requires technical and organisational measures appropriate to the risk. Group Security defines the measures applied to this site, and the Data Protection Office verifies that they cover the processing operations entered in the record.
- Every submission is validated again on the server. Validation performed by the browser is a convenience and is not treated as a guarantee.
- No personal data is written to the application logs. The three form routes record the outcome of a submission and, for an application, the role applied for — never a name, an address, a message or a file name.
- A CV is accepted only if its first bytes match the format it declares: PDF, the ZIP container of a DOCX or an ODT, or the OLE2 container of a legacy DOC. Its size is capped at 5 MB. The check bears on the format and is not a virus scan.
- The file name sent with a CV is stripped of path separators and of characters that a downstream system could interpret.
- The forms are rate limited by IP address, as entered in the record.
- Transport is encrypted and pinned by a two-year HTTP Strict Transport Security policy with preload. The content security policy allows scripts, styles, images, fonts and connections from this origin only; framing is denied outright; the permissions policy denies camera, microphone, geolocation and interest-cohort access.
- The site ships no third-party JavaScript, loads no remote image and no remote font, and calls no external mapping or font service. The office map is drawn from data held in the site itself.
- Access to a submission is limited to the members of the department concerned who need it to answer, and each regional company is bound by the same instructions.
Where a personal data breach occurs and is likely to result in a risk to the rights and freedoms of the people concerned, the Data Protection Office, with Group Security, notifies the competent supervisory authority within 72 hours under Article 33 of the GDPR and informs the people concerned directly where Article 34 requires it. Every breach, whether or not it is notified, is entered in the record kept under Article 33(5). The equivalent notification duties of the Nigerian, Kenyan, Congolese, Emirati and Singaporean laws are met in the same movement.
Your rights
The rights below are those of Regulation (EU) 2016/679 and of the UK GDPR. Each is stated with the provision that founds it and the period within which the group answers.
- Access — obtain confirmation that data concerning you is processed, a copy of that data, and the information in this policy applied to your own case (Art. 15; answered within one month).
- Rectification — have inaccurate data corrected and incomplete data completed (Art. 16; answered within one month, and the correction is passed to every recipient of the data).
- Erasure — have data deleted where one of the grounds in Article 17 applies, in particular where you withdraw the consent on which the processing rests or where the retention period has expired (Art. 17; answered within one month).
- Restriction — have processing frozen while a challenge to the accuracy of the data or to a legitimate interest is determined (Art. 18; answered within one month, and you are informed before the restriction is lifted).
- Portability — receive the data you provided, in a structured, commonly used and machine-readable format, and have it transmitted to another controller where that is technically feasible (Art. 20; answered within one month).
- Objection — object at any time, on grounds relating to your particular situation, to processing based on legitimate interest (Art. 21; answered within one month, and the processing stops unless the group demonstrates compelling legitimate grounds).
- Withdrawal of consent — withdraw at any time, without giving a reason and as easily as consent was given (Art. 7(3); effective on receipt and no later than 30 days afterwards).
- Not to be subject to a decision based solely on automated processing (Art. 22; no such decision is taken here, as the section “Automated decisions” states).
- Complaint to a supervisory authority — lodge a complaint with the authority of your choice among those competent, without having to apply to the group first (Art. 77; the authorities are listed in the section “Complaining to an authority”).
The laws that apply to the group outside Europe grant rights of the same nature, and they are exercised by the same route and answered by the Data Protection Office.
- Nigeria — Nigeria Data Protection Act 2023: rights to be informed, of access, of rectification, of erasure, of restriction, of portability, to object to processing and to withdraw consent. Complaints are made to the Nigeria Data Protection Commission.
- Kenya — Data Protection Act, 2019, section 26: rights to be informed of the use of the data, of access, to object to processing, to correction of false or misleading data, to deletion, and to portability. Complaints are made to the Office of the Data Protection Commissioner.
- Democratic Republic of the Congo — ordonnance-loi n° 23/010 of 13 March 2023 (code du numérique) and loi n° 20/017 of 25 November 2020: rights to information, of access, of rectification, of deletion and to object, exercised with the group at its registered office in Kinshasa and before the authority designated by the code du numérique.
- United Arab Emirates — Federal Decree-Law No. 45 of 2021, Articles 13 to 17: rights to obtain information about the processing, to data portability, to rectification or erasure, to restriction of processing and to object. Complaints are made to the UAE Data Office.
- Singapore — Personal Data Protection Act 2012: right to withdraw consent (section 16), right of access (section 21) and right of correction (section 22). Complaints are made to the Personal Data Protection Commission.
- California — California Consumer Privacy Act as amended by the CPRA: rights to know, to delete, to correct, to opt out of the sale or sharing of personal information, to limit the use of sensitive personal information and not to be discriminated against for exercising them (Cal. Civ. Code §§ 1798.100 to 1798.125), answered within 45 days and extendable once by a further 45 days (§ 1798.130). The section “Residents of California” sets out how they apply here.
Complaining to an authority
You are not required to apply to the group first, and nothing in this policy limits that right. Article 77 of the GDPR, and the equivalent provisions of the other laws listed below, allow you to complain directly to the authority competent for your situation.
| Jurisdiction | Instrument | Authority |
|---|---|---|
| European Union and European Economic Area | Regulation (EU) 2016/679, Article 77 | The supervisory authority of your Member State of residence, of your place of work, or of the place of the alleged infringement |
| United Kingdom | UK GDPR; Data Protection Act 2018 | Information Commissioner’s Office (ICO) |
| Democratic Republic of the Congo | Ordonnance-loi n° 23/010 du 13 mars 2023 (code du numérique); loi n° 20/017 du 25 novembre 2020 | The authority designated under the code du numérique |
| Nigeria | Nigeria Data Protection Act 2023 | Nigeria Data Protection Commission (NDPC) |
| Kenya | Data Protection Act, 2019 | Office of the Data Protection Commissioner (ODPC) |
| United Arab Emirates | Federal Decree-Law No. 45 of 2021 | UAE Data Office |
| Singapore | Personal Data Protection Act 2012 | Personal Data Protection Commission (PDPC) |
| California | Cal. Civ. Code §§ 1798.100 et seq. | California Privacy Protection Agency; California Attorney General |
A complaint may also be addressed to the Data Protection Office at contact@parousiagroup.com, which answers within one month. Doing so neither suspends nor limits the right to apply to a supervisory authority, and it does not affect the judicial remedies available under Articles 78 and 79 of the GDPR.
Residents of California
This section is given under the California Consumer Privacy Act as amended by the CPRA. In the categories of Cal. Civ. Code § 1798.140(v), the site collects identifiers (name, email address, telephone number, IP address), professional or employment-related information (the content of an application and the CV attached to it), internet activity information limited to the server logs described in the record, and the content of the electronic communications you choose to send through the contact form. It collects no biometric information, no geolocation data, no government identifier and no financial account information.
Each category is collected from the consumer alone, for the purpose stated against it in the record above, disclosed only to the recipients listed in the section “Who receives the data”, and kept for the period stated in the record. No category is disclosed to a third party for that third party’s own commercial purposes.
Children
These sites are addressed to institutions, clients, journalists and candidates for employment. They are not directed at children, no service offered here is an information society service offered directly to a child within the meaning of Article 8 of the GDPR, and the group does not knowingly collect data from a person below the age at which their country allows them to work.
Where the group learns that it holds data relating to such a person, the Data Protection Office deletes it. A parent or guardian who considers that a child has sent personal data through this site may write to contact@parousiagroup.com, and the data is deleted without the requester having to establish anything beyond the circumstances of the sending.
Changes to this policy
This document carries a version number, a review date and an effective date, and all three are displayed. A change that adds a purpose, a recipient, a transfer or a longer retention period raises the version number and is announced on the site before it takes effect. A correction of wording that changes nothing in substance raises the minor number only.
Earlier versions are kept by the Group Secretariat, and a copy of the version in force on a given date is sent on request to contact@parousiagroup.com. The Data Protection Office reviews this policy at least once a year and whenever a processing operation, a recipient or a retention period changes.
Base normativa
- Regulation (EU) 2016/679 (GDPR) — Articles 4, 6, 9, 12 to 22, 28, 30, 32, 44 to 49 and 77
- UK GDPR and Data Protection Act 2018 (c. 12)
- Directive 2002/58/EC (ePrivacy) as amended by Directive 2009/136/EC — Article 5(3)
- Commission Implementing Decision (EU) 2021/914 — standard contractual clauses
- CJEU, 16 July 2020, Data Protection Commissioner v Facebook Ireland and Schrems, C-311/18
- Nigeria Data Protection Act 2023
- Kenya Data Protection Act, 2019 (No. 24 of 2019)
- République démocratique du Congo — loi n° 20/017 du 25 novembre 2020 relative aux télécommunications et aux technologies de l’information et de la communication
- République démocratique du Congo — ordonnance-loi n° 23/010 du 13 mars 2023 portant code du numérique
- United Arab Emirates — Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
- Singapore Personal Data Protection Act 2012 (No. 26 of 2012)
- California Consumer Privacy Act as amended by the CPRA — Cal. Civ. Code §§ 1798.100 et seq.
Todos los documentos legales
- Política de cookiesQué guardamos en tu dispositivo y por qué.
- Términos y condicionesLas condiciones que rigen el uso de este sitio web.
- Declaración de accesibilidadNuestro compromiso con el nivel AA de las WCAG 2.2, lo que hemos hecho y cómo notificar una barrera.
- Divulgación de vulnerabilidadesCómo notificar un fallo de seguridad, a qué se compromete el grupo y qué protección reciben los investigadores.
- CumplimientoNuestros compromisos regulatorios, de seguridad y éticos en todos los mercados en los que operamos.
- Lucha contra el soborno y la corrupciónLo que el grupo prohíbe sin excepción y cómo se hace cumplir esa prohibición.
- Denuncia de irregularidadesCómo denunciar una conducta indebida, qué ocurre después y la protección que te otorga la ley.
- Esclavitud moderna y trabajo forzosoDónde se sitúa el riesgo en las cadenas de suministro del grupo y qué se está haciendo al respecto.
- Aviso legalQuién publica este sitio, bajo qué identidad y dónde dirigir una notificación formal.
Contactar con el grupo contact@parousiagroup.com
