GDPR

Privacy Policy

Last updated: February 2026

Introduction

ATSA® International attaches paramount importance to the protection of your personal data. This privacy policy explains what data we collect, why, how we use it, and what your rights are. We act in compliance with the General Data Protection Regulation (GDPR).

1. Data Collected

We collect the following data, depending on your interactions with the Site:

Identification data:

First name, last name, email, phone number

Professional data:

Professional situation, position, company, request description (Bilan Booster forms, 360° Audit)

Navigation data:

IP address, pages visited, visit duration, browser type (via cookies and analytics)

Order data:

Purchase history, products or services subscribed, amounts (if purchase via shop)

2. Processing Purposes

Your data is collected and processed for the following purposes:

  • Respond to your contact, assessment or audit requests
  • Manage the commercial relationship and perform services
  • Send communications related to subscribed services
  • Improve the Site and our services (statistics, analytics)
  • Comply with our legal obligations (invoicing, accounting)
  • With your consent: send newsletters or marketing communications

3. Legal Basis for Processing

We process your personal data on the following legal bases:

  • Contract performance: to manage your orders and services
  • Legitimate interest: to improve our services and ensure Site security
  • Consent: for sending marketing communications (you can withdraw this consent at any time)
  • Legal obligation: to meet our accounting and tax obligations

4. Retention Period

We retain your data only as long as necessary for the purposes for which it was collected:

  • Contact requests: 3 years after last contact
  • Active clients: duration of commercial relationship + 3 years
  • Accounting data: 10 years (legal obligation)
  • Cookies and analytics data: 13 months maximum

5. Data Recipients

Your personal data is intended for:

  • ATSA® International internal teams (consultants, customer service)
  • Our technical subcontractors (hosting, emailing, payment), in compliance with GDPR
  • Competent authorities, if required by law

We do not sell or rent your data to third parties for commercial purposes.

6. Security

We implement technical and organizational measures to protect your data against any unauthorized access, modification, disclosure or destruction:

  • Secure hosting with data encryption (SSL/TLS)
  • Restricted data access (authentication, access rights)
  • Regular backups
  • Security incident management procedures

7. Your Rights

In accordance with GDPR, you have the following rights:

  • Right of access: obtain a copy of your data
  • Right to rectification: correct inaccurate data
  • Right to erasure: request deletion of your data
  • Right to restriction: limit processing in certain cases
  • Right to object: object to the processing of your data (prospecting, legitimate interest)
  • Right to portability: retrieve your data in a structured format
  • Right to withdraw consent: at any time, for consent-based processing

To exercise your rights, see our dedicated page: Data Subject Rights.

8. Data Transfer Outside EU

Your data is hosted within the European Union. If we need to transfer your data outside the EU, we will ensure appropriate safeguards are in place (standard contractual clauses, adequacy decision).

9. Contact

For any questions regarding the protection of your data or to exercise your rights, contact us:

Email: contact@atsa-international.com

Responsible: Liuzzo Sonia

You also have the right to lodge a complaint with the CNIL (French Data Protection Authority) – www.cnil.fr