Cloud Formity Personal Data Policy
Last updated: 04/08/2026
1. Introduction
The protection of personal data is a priority for Thales. This Personal Data Policy (the “Policy”) describes how Thales S.A. (“Thales”, “we”, “us”) processes personal data in connection with the Cloud Formity customer portal (the “Portal”), in compliance with Regulation (EU) 2016/679 of 27 April 2016 (the “GDPR”) and the French Data Protection Act (loi Informatique et Libertés).
This Policy is issued in application of Thales's Binding Corporate Rules for Controllers (“BCR-C”), approved by the French Data Protection Authority (CNIL) by deliberations n° 2023-144 and n° 2023-145 of 21 December 2023, which constitute Thales's global personal data protection policy applicable across all Thales entities, including Thales S.A. The public version of the BCR-C is available here. Where this Policy does not address a specific point, the BCR-C apply.
This Policy applies to personal data collected from users of the Portal, client contacts, prospects and any other individual whose personal data is processed in the context of the Portal, as described in Section 4 below.
This Policy does not cover the use of cookies and similar tracking technologies on the Portal, which is addressed separately in our Cookie Policy.
2. Who is the data controller?
The data controller for the personal data processed through the Portal is:
Thales S.A.
A société anonyme (S.A.) registered with the Nanterre Trade and Companies Register (RCS) under number 552 059 024, with registered office at 4, rue de la Verrerie, 92190 Meudon, France.
3. Data Protection Officer and contact
For any question relating to this Policy or to the processing of your personal data, or to exercise your rights (see Section 8), you may contact the Thales Group Data Protection Officer at:
dataprotection@thalesgroup.com
4. What personal data do we collect, and why?
We process personal data for the following purposes:
| Purpose of processing | Personal data processed | Categories of data subjects | Legal basis | Retention period |
|---|---|---|---|---|
| User account management | Login ID, password, first name, last name, email address, phone number, job title | Client contacts, portal users, Thales users | Performance of a contract (Art. 6(1)(b) GDPR) | For the duration of the contract |
| Customer support | First name, last name, email address | Portal users, Thales users | Performance of a contract (Art. 6(1)(b) GDPR) | Inactive tickets: 1 year in an archive table, then permanently deleted after a further 3 months |
| Operational communications | First name, last name, email address, job title | Portal users | Performance of a contract (Art. 6(1)(b) GDPR) | For the duration of the contract |
| Portal security (logging, fraud prevention, incident detection) | Email address, IP address, timestamp | Portal users, Thales users, client contacts | Legitimate interest (Art. 6(1)(f) GDPR) — IT and information system security | 12 months* |
| Commercial prospecting and newsletters | First name, last name, email address, job title | Prospects, portal users, client contacts | Legitimate interest (Art. 6(1)(f) GDPR) for B2B prospecting; consent (Art. 6(1)(a) GDPR) for newsletter subscription | 3 years from the last contact with the data subject (prospecting); for the duration of the subscription (newsletter) |
| Usage statistics and service improvement | Company domain, IP address, timestamp, visitor ID (VID), pages visited | Portal users, prospects | Legitimate interest (Art. 6(1)(f) GDPR) | 6 months |
| Electronic signature of documents | First name, last name, email address, phone number, signature | Signatories of contractual documents | Performance of a contract (Art. 6(1)(b) GDPR); legal obligation to retain evidence (Art. 6(1)(c) GDPR) | 3 years from the last login to the e-signature platform |
* The retention period for portal security logs has been set at 12 months, in line with the general 6-month to 1-year range recommended by the CNIL (Deliberation No. 2021-122 of 14 October 2021) for security and connection logs.
Thales does not process special categories of personal data (e.g. data revealing racial or ethnic origin, health data, biometric data) through the Portal.
Providing certain personal data is necessary for Thales to perform the contract and to provide you with access to the Portal (e.g. for account creation, or for the electronic signature of contractual documents). Should you not provide this data, Thales may be unable to create your account or provide the corresponding service.
5. Who has access to your personal data?
Your personal data is accessed by authorised Thales personnel on a need-to-know basis. It may also be shared with the following categories of recipients:
| Purpose(s) | Recipient / sub-processor | Location | Safeguards |
|---|---|---|---|
| Portal hosting; user account management; customer support and ticketing; operational communications; commercial prospecting and newsletters; usage statistics | HubSpot (CRM, marketing automation, ticketing/support and hosting platform on which the Portal operates — “EU1” hosting cluster) | Primary data centre: Frankfurt (Germany); replicated to Dublin (Ireland) — European Union. Underlying provider: HubSpot, Inc. (United States) | HubSpot, Inc. is self-certified under the EU-U.S. Data Privacy Framework (European Commission adequacy decision of 10 July 2023, Art. 45 GDPR); HubSpot's Data Processing Agreement additionally incorporates the European Commission's Standard Contractual Clauses as a subsidiary mechanism |
| Electronic signature of documents | Dropbox Sign (Dropbox, Inc.) | United States (Dropbox, Inc.) | Dropbox, Inc. is self-certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR); Thales should confirm that the specific Dropbox Sign product/entity is included in the current certification scope on dataprivacyframework.gov before publication |
6. Do we transfer your personal data outside the European Union?
The Portal is hosted on HubSpot's “EU1” hosting cluster, with data stored primarily in Frankfurt (Germany) and replicated to Dublin (Ireland), i.e. within the European Economic Area (EEA).
However, the underlying providers used for the Portal (HubSpot, Inc.) and for the electronic signature of documents (Dropbox, Inc., via Dropbox Sign) are US-based companies. Personal data may therefore be accessed from, or transferred to, the United States, in particular for technical support and account administration purposes.
These transfers are carried out on the basis of the EU-U.S. Data Privacy Framework (“DPF”), an adequacy decision adopted by the European Commission on 10 July 2023 pursuant to Article 45 of the GDPR. Under this mechanism, personal data can be transferred to self-certified US companies without the need for additional safeguards such as Standard Contractual Clauses. HubSpot, Inc. and Dropbox, Inc. are both self-certified under the DPF.
You may request more information on, or a copy of, the safeguards applicable to these transfers by contacting the individuals listed in section 3.
7. How do we protect your personal data?
Thales implements technical and organisational measures designed to ensure a level of security appropriate to the risk, including in particular:
- Access controls and authentication mechanisms restricting access to personal data to authorised personnel only;
- Encryption of data in transit and, where applicable, at rest;
- Logging and monitoring of access to the Portal for security and fraud-prevention purposes;
- Regular review and testing of security measures in line with Thales Group information security policies.
8. What are your rights?
In accordance with the GDPR, you have the following rights over your personal data:
- Right of access: to obtain confirmation of whether your personal data is processed, and a copy of that data;
- Right to rectification: to have inaccurate or incomplete personal data corrected;
- Right to erasure: to have your personal data deleted, subject to applicable legal retention requirements;
- Right to restriction of processing: to limit how your personal data is used in certain circumstances;
- Right to object: to object to the processing of your personal data carried out on the basis of legitimate interest, including for prospecting purposes;
- Right to data portability: to receive the personal data you have provided to us in a structured, commonly used, machine-readable format;
- Right to withdraw consent: where processing is based on your consent (e.g. newsletter subscription), you may withdraw it at any time.
Thales does not use your personal data to make decisions based solely on automated processing (including profiling) that produce legal effects concerning you or significantly affect you, within the meaning of Article 22 GDPR.
To exercise these rights, please contact the Thales Group Data Protection Officer (Délégué à la Protection des Données du Groupe) at the address indicated in Section 3. You may be asked to provide proof of identity.
In accordance with the Thales BCR-C (Section 11), we will handle your request without undue delay and, in any event, within one (1) month of receipt. This period may be extended by a further two (2) months where necessary, taking into account the complexity and number of requests; if so, we will inform you of the extension and the reasons for the delay within one (1) month of receiving your request.
9. Your rights as a third-party beneficiary of the Thales BCR-C
As Thales applies Thales's Binding Corporate Rules for Controllers (BCR-C), you may, as a third-party beneficiary, invoke the following Sections and Annexes of the BCR-C directly against Thales:
- Section 1 (Introduction), Section 2 (Scope), Section 3 (Binding legal effect of the BCR-C);
- Section 4 (Essential principles relating to the processing of personal data), Section 5 (Processing of sensitive personal data);
- Section 6 (Personal data breach), Section 7 (Processing by a third party or an internal processor);
- Section 8 (Transfer of personal data to a third country or an international organisation), Section 9 (Liability);
- Section 10 (Rights of data subjects), Section 11 (Procedure for handling requests to exercise rights), Section 12 (Procedure for handling complaints from data subjects);
- Section 13 (Data protection by design / by default), Section 14 (Data protection impact assessment), Section 15 (Record of processing activities);
- Section 16 (Cooperation with the competent data protection authorities), Section 17 (Transparency), Section 21 (Update of the BCR-C);
- Annex 1 (List of processing purposes carried out by Thales as controller) and Annex 2 (Thales entities bound by the BCR-C).
The public version of the BCR-C, including these Sections, is available here.
10. How to submit a complaint
If you consider that Thales has failed to comply with this Policy or with applicable data protection law, you may submit a complaint directly to us using the contact details in Section 3.
In accordance with the Thales BCR-C (Section 12), we will handle your complaint without undue delay and, in any event, within one (1) month of receipt, through a function with an appropriate level of independence. This period may be extended by a further two (2) months where necessary; if so, we will inform you within one (1) month of receiving your complaint and explain the reasons for the delay.
Whether or not you have first submitted a complaint to Thales, and whether or not you are satisfied with our response, you have the right to lodge a complaint directly with the French supervisory authority, the Commission Nationale de l'Informatique et des Libertés (CNIL) 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — or with the supervisory authority of your country of residence, place of work, or place of the alleged infringement, and/or to bring proceedings before the competent court.
11. Cookies
The Portal uses cookies and similar technologies. For more information on the cookies used, their purpose and how to manage your preferences, please refer to our Cookie Policy.
12. Changes to this Policy
We may update this Policy from time to time, in particular to reflect changes in our processing activities or in applicable law. The date of the last update is indicated at the top of this Policy. We encourage you to review this Policy periodically.
13. Contact
For any question regarding this Policy or the processing of your personal data through the Portal, please contact:
The Thales Group Data Protection Officer: dataprotection@thalesgroup.com
