Privacy Policy

YesWeHack (hereafter “YesWeHack”) administers the following sites:

This Personal Data Protection Policy applies to the said sites (hereafter the “Sites”).

Regarding the use of the YesWeHack platform, available at https://yeswehack.com/auth/login:

  • The Personal Data Protection Policy applying to Hunters is provided here.
  • The Personal Data Protection Policy applying to Users is provided here.

When you are browsing and using the services offered on the Sites, YesWeHack processes your Personal Data in accordance with current regulations, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of Personal Data (hereafter “the GDPR”), as well as (French) law no. 78-17 of 6 January 1978 amended.

For the interpretation of notions relating to the protection of Personal Data in this Policy, please refer to the definitions in the Terms and Conditions of Use of the Sites and the definitions set out below.

IMPORTANT DEFINITIONS

  • Personal Data is any information relating to an identified or identifiable person that identifies the person directly (e.g. the surname and the first name) or indirectly (e.g. connection data). (Article 4-1 of the GDPR)
  • Processing (of Personal Data) is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as: collection, recording, organisation, storage, disclosure by transmission, etc. (Article 4-2 of the GDPR)
  • The Controller determines the purposes and means of Processing. (Article 4-7 of the GDPR)
  • The Processor processes Personal Data on behalf of and on the instructions of the Controller. (Article 4-8 of the GDPR)

WHAT IS YESWEHACK’S ROLE?

Depending on your actions on the Sites (browsing, using their services), YesWeHack collects your Personal Data needed for the purposes stated below:

Purposes: Production of statistics/web analytics

Legal basis: Article 6-1(f) of the GDPR: for the purposes of the legitimate interests [pursued by the Controller], in accordance with the fundamental rights and freedoms of the data subjects

[YesWeHack’s legitimate interest: measurement and development of the blog’s activity based on aggregate indicators]

Purposes: Performance analysis and measurement via third-party cookies

Legal basis: Article 6-1(a) of the GDPR – Consent to Data Processing

Purposes: Presentation of relevant advertisements via third-party cookies

Legal basis: Article 6-1(a) of the GDPR – Consent to Data Processing

Purposes: Management of requests to exercise GDPR rights

Legal basis: Article 6-1 (c) of the GDPR – Compliance with a legal obligationManagement of disputesArticle 6-1(f) of the GDPR – for the purposes of the legitimate interests [pursued by the Controller], in accordance with the fundamental rights and freedoms of the data subjects

[YesWeHack’s legitimate interest: defense of their rights]

Purposes:  Administration of the YesWeHack site

Legal basis: Article 6-1(f) of the GDPR: for the purposes of the legitimate interests [pursued by the Controller], in accordance with the fundamental rights and freedoms of the data subjects

[YesWeHack’s legitimate interest: site management]

Purposes: Management of the contact form

Legal basis: Article 6-1(f) of the GDPR – for the purposes of the legitimate interests [pursued by the Controller], in accordance with the fundamental rights and freedoms of the data subjects

[YesWeHack’s legitimate interest: responding to your request]

Purposes: Administration of the blog

Legal basis: Article 6-1(f) of the GDPR: for the purposes of the legitimate interests [pursued by the Controller], in accordance with the fundamental rights and freedoms of the data subjects

[YesWeHack’s legitimate interest: blog management]

Purposes: Managing form's

Legal basis: Article 6-1(f) of the GDPR – for the purposes of the legitimate interests [pursued by the Controller], in accordance with the fundamental rights and freedoms of the data subjects

[YesWeHack’s legitimate interest: responding to the user’s request]

Purposes: Sending YesWeHack’s marketing updates

Legal basis: Article 6-1(a) of the GDPR – consent to the Processing of [his or her] Personal DataRequest to contact a sales representativeArticle 6-1(a) of the GDPR – consent to the Processing of [his or her] Personal Data

If you apply for a job via the site: your Personal Data is managed by Welcome to the Jungle, which acts as Controller within the meaning of the GDPR. All the information concerning the Processing of your personal Data can be accessed at the following address: https://www.welcometothejungle.com/fr/pages/privacy-policy

WHAT CATEGORIES OF PERSONAL DATA ARE COLLECTED AND PROCESSED BY YESWEHACK?

Depending on which services are used, your Personal Data processed by YesWeHack includes:

  • The contact form on the YesWeHack site: form of address, full name, e-mail address, telephone number.
  • Forms on the blog (White paper, Newsletter or other forms): e-mail address, job, employer, and optionally your full name and telephone number.
  • Administration of the Sites: login data (IP address, date and time of login, location)
  • Statistics/audience measurement: aggregated (anonymous) data.
  • Performance analysis and measurement via third-party cookies: login data, data from cookies (navigation on the Sites).
  • Presentation of adapted advertisements via third-party cookies: data from cookies (navigation on the Sites).
  • Management of requests to exercise GDPR rights: name, first name, e-mail, information related to the request.
  • Management of litigation: any Personal Data strictly necessary to defend the rights of YesWeHack.

WHO ARE THE RECIPIENTS OF YOUR PERSONAL DATA?

Internal recipients of your Personal Data: the recipient of your Personal Data are the authorized staff of YesWeHack.

The external recipients of your Personal Data are Processors who process data on behalf of YesWeHack:

  • OVH, the data hosting company in France.
    OVH – 2 rue Kellermann – 59100 ROUBAIX
  • HubSpot Inc., the company that hosts and manages data in the forms.
    HubSpot Headquarters – 25 First Street – Cambridge, MA 02141 – United States

For third-party cookies:

The company Google LLC. whose privacy policy can be accessed at the following address: https://policies.google.com/privacy?hl=en-GB

The company Hubspot Inc. whose privacy policy can be accessed at the following address: https://legal.hubspot.com/dpa

In this context, transfers of Personal Data to these partners are governed by appropriate safeguards in accordance with Article 46 of the GDPR:

FOR HOW LONG IS YOUR PERSONAL DATA STORED?

  • Administration of the Sites: login data is kept for 6 months
  • Data in forms: your Personal Data is kept for 2 years from the time of YesWeHack’s last contact with you, they will be deleted after the end of this period.
  • For the Newsletter or news about upcoming events: your Personal Data is erased within one month after you exercise your opt-out option.
  • For the request to contact a sales representative: your Personal Data is kept for 2 years from the time of YesWeHack’s last contact with you, they will be deleted after the end of this period.
  • For third-party cookies: the storage period is a maximum of 13 months.
  • Management of requests to exercise GDPR rights: your Personal Data is kept for 6 years for the exercise of the right of opposition (criminal prescription) and for 5 years for other rights (civil prescription).

WHAT ARE YOUR RIGHTS?

Regarding the use of the Sites, you have the following rights under the conditions provided for in the regulations:

  • The right of access, rectification and erasure of your data (articles 15 to 17 of the GDPR);
  • The right to withdraw your consent (opt out) at any time (article 13-2(c) of the GDPR);
  • The right to restriction of Processing of your data (article 18 of the GDPR);
  • The right to object the Processing of your data (article 21 of the GDPR);
  • The right to data portability (article 20 of the GDPR);
  • The right to file a complaint with the CNIL (the French data protection authority) (https://www.cnil.fr/fr/plaintes);
  • The right to issue instructions allowing access to your data in the event of death (article 85 of the modified “Informatique et Liberté” French Act).

You can exercise these rights by e-mail at privacy@yeswehack.com, specifying the right you wish to exercise and attaching proof of your identity (if necessary) or a power of attorney if you are being represented.

Contact details of the DPO (Data Protection Officer): privacy@yeswehack.com

ARE THERE COOKIES ON YESWEHACK?

All information relating to cookies and their settings is available here and on all pages of the Sites.