Data Protection and Cookies Policy
1. Purpose of this Policy
This Data Protection and Cookies Policy explains how WYDIN SAS, publisher of the Orcheo service, collects, uses, protects and retains personal data processed in connection with the website www.orcheo.com, the Orcheo application and the associated services.
It applies in particular to:
- website visitors;
- prospects requesting a demonstration, trial, information or sales contact;
- professional clients using Orcheo;
- users authorized by a client to access Orcheo;
- persons whose data may appear in financial, banking or management data processed by a client in Orcheo.
Orcheo is a professional SaaS solution enabling businesses in particular to centralize, monitor, analyze and forecast their cash position, financial flows and certain management indicators, with automation and artificial intelligence features.
This Policy is intended to provide clear, transparent and accessible information on the personal data processing carried out by Orcheo, in accordance with the General Data Protection Regulation, the French Data Protection Act (Loi Informatique et Libertés) and other applicable data protection regulations.
It specifies in particular:
- what data may be collected;
- why such data is processed;
- on what legal bases;
- with whom it may be shared;
- how long it is retained;
- what rights may be exercised;
- how Orcheo uses cookies and trackers;
- how to contact Orcheo for any question relating to personal data.
2. Who is the Data Controller?
The data controller is:
WYDIN SAS
French simplified joint-stock company (société par actions simplifiée) with share capital of €10,000
Registered under number 921 024 188 RCS Paris
Registered office: 61 Rue Emeriau, 75015 Paris, France
Contact: privacy@orcheo.com
WYDIN SAS acts as data controller when it determines the purposes and means of processing, in particular for:
- managing the Orcheo website;
- managing requests for contact, demonstrations or trials;
- creating and administering accounts;
- commercial and contractual management;
- billing and payment;
- customer support;
- security of the website and application;
- service improvement;
- marketing communications, where applicable;
- managing data subject rights.
Where WYDIN SAS processes personal data integrated, imported or connected by a Client into Orcheo for the Client’s own purposes, WYDIN SAS in principle acts as processor for the Client. In such case, the Client remains the data controller and the applicable terms are set out in the Terms of Use and Service and in the Data Processing Agreement.
3. What Data is Collected?
Orcheo may collect different categories of personal data depending on your relationship with Orcheo and your use of the website or application.
Such data may come from:
- information you provide directly;
- your browsing of the website;
- your use of the application;
- information entered by your company or by an administrator;
- banking or financial connections activated by your company;
- third-party providers used to provide the service;
- exchanges with the Orcheo teams.
The main categories of data that may be collected are:
- identification data: surname, first name, role, company;
- contact data: professional email address, telephone number, professional address;
- account data: credentials, role, permissions, organization, settings;
- contractual and billing data: subscription, quotes, invoices, payment, VAT, subscription history;
- usage data: logs, IP address, device, browser, actions performed in the application, settings, technical events;
- support data: messages, tickets, requests, attachments, exchanges with the Orcheo teams;
- marketing data: forms, communication preferences, subscription to content, interactions with emails;
- banking and financial data processed in the application;
- data generated or inferred by Orcheo: categories, analyses, forecasts, alerts, rules, internal scores, summaries and results produced by automation or artificial intelligence features.
Orcheo is not intended to collect special categories of data within the meaning of the GDPR, such as data relating to health, political opinions, religious beliefs, racial or ethnic origin, sexual orientation, biometric data or genetic data, unless such data is voluntarily included by a Client in free-text fields, documents, labels or imported data. The Client must avoid including such data in Orcheo where it is not necessary.
4. Account Data
When you create an account, are invited to use Orcheo or use the application on behalf of a Client, Orcheo may process the following data:
- surname and first name;
- professional email address;
- professional telephone number, where applicable;
- position or role within the company;
- name of the company or organization;
- user identifier;
- password or authentication data, in secured form;
- role in the application: owner, administrator, editor, viewer or any other available role;
- access rights and permissions;
- entities, accounts, workspaces or scopes to which the user has access;
- account status: active, invited, suspended, deleted;
- language preferences, time zone, notifications and settings;
- login and activity history;
- security logs;
- information relating to email verification, password reset or enhanced authentication.
This data is used in particular to:
- create and manage accounts;
- enable secure access to the application;
- authenticate users;
- manage roles and access rights;
- administer the subscription;
- provide the service;
- provide support;
- prevent unauthorized access, fraud or abuse;
- keep reasonable traceability of actions performed in the application.
Some account data is necessary for the performance of the contract or for the security of the service. Failure to provide such data may prevent access to all or part of Orcheo.
5. Banking and Financial Data
When the Client uses bank connection, financial import, forecasting or cash analysis features, Orcheo may process banking and financial data relating to the Client’s professional activity.
This data may include in particular:
- name of the bank or financial institution;
- technical connection or synchronization identifiers, depending on the providers used;
- name or label of the connected accounts;
- account type;
- currency;
- balances;
- transaction history;
- transaction, value or accounting dates;
- amounts;
- transaction labels;
- flow direction: inflow or outflow;
- payment or transaction references;
- counterparties: clients, suppliers, partners or other third parties;
- categories and subcategories;
- recurring or exceptional transactions;
- flow forecasts;
- comments, rules, tags or annotations added by the Client;
- analyses, alerts, summaries, anomalies or forecasts generated by Orcheo.
This data may contain personal data where it directly or indirectly identifies a natural person, for example a director, user, sole trader, supplier, client, beneficiary or counterparty mentioned in a bank transaction label.
Banking and financial data is used in particular to:
- connect accounts authorized by the Client;
- centralize financial information;
- display balances and transactions;
- monitor the cash position;
- categorize flows;
- detect recurring transactions;
- identify certain anomalies or variations;
- produce cash flow forecasts;
- generate dashboards, reports, summaries or analyses;
- improve the reliability and security of the service;
- provide technical support in the event of an incident.
Orcheo does not hold the Client’s funds, does not execute payment transactions on behalf of the Client and is not a bank, payment institution or account information service provider. Bank connections are based on the authorizations given by the Client and, where applicable, on specialized third-party providers.
The Client’s banking and financial data is not used to train generic or non-customized artificial intelligence models, unless specifically agreed by the Client or where processing is carried out using aggregated, anonymized data or data that does not identify the Client, its users or any data subject.
6. Data Imported by the Client
In connection with the use of Orcheo, the Client may import, enter, connect, transmit or generate various data in the application.
Such data may include in particular:
- financial files, documents, spreadsheets or exports;
- treasury data, budgets, forecasts, scenarios or assumptions;
- accounting or management data;
- categories, rules, tags, comments, notes or annotations;
- information relating to clients, suppliers, partners or other counterparties;
- information relating to entities, subsidiaries, accounts, currencies, countries, cost centers or operational units;
- data integrated through third-party tools, accounting software, ERPs, bank files or other connected sources;
- content transmitted to Orcheo support or teams.
This data may contain personal data where it directly or indirectly identifies a natural person, including a director, employee, contractor, client, supplier, sole trader, financial contact or payment beneficiary.
Where such data is imported or connected by the Client for its own purposes, the Client acts as data controller and WYDIN SAS acts as processor, under the conditions set out in the Terms of Use and Service and the Data Processing Agreement.
The Client is responsible for the lawfulness, accuracy, relevance and updating of the data it imports or connects into Orcheo.
The Client undertakes not to intentionally import sensitive or unnecessary data, including data relating to health, political opinions, religious beliefs, racial or ethnic origin, sexual orientation, biometric or genetic data, unless this is strictly necessary, lawful and subject to appropriate safeguards.
7. Usage Data, Logs and Security
When you use the Orcheo website or application, WYDIN SAS may collect technical, usage and security data.
This data may include in particular:
- IP address;
- date and time of connection;
- user identifier;
- device type;
- browser;
- operating system;
- language;
- country or approximate connection area;
- pages viewed;
- features used;
- technical events;
- actions performed in the application;
- access, administration, modification, export or connection logs;
- errors, incidents, crashes or slowdowns;
- login attempts;
- security settings;
- data relating to cookies and trackers.
This data is used in particular to:
- enable the technical operation of the website and application;
- authenticate users;
- secure accounts;
- prevent unauthorized access;
- detect abnormal, abusive or fraudulent behavior;
- diagnose and correct incidents;
- improve service performance and stability;
- produce usage statistics;
- keep reasonable traceability of actions performed in the application.
Some usage data is necessary for the operation and security of Orcheo. Other data, in particular data from non-essential cookies or marketing analytics tools, is processed according to your consent choices where consent is required.
8. Marketing and Support Data
WYDIN SAS may collect and process data in connection with its marketing, sales and support activities.
This data may include in particular:
- surname, first name;
- role;
- company;
- professional email address;
- professional telephone number;
- country;
- company size or sector;
- request for a demonstration, trial or contact;
- exchanges with sales or support teams;
- support tickets;
- messages sent through the website, application, email, chat or CRM;
- attachments or screenshots voluntarily transmitted;
- history of interactions with Orcheo;
- communication preferences;
- subscription to content, newsletters, events or resources;
- interactions with Orcheo emails, pages or campaigns.
This data is used in particular to:
- respond to contact requests;
- organize demonstrations;
- manage free trials;
- provide customer support;
- handle incidents;
- support onboarding;
- send service-related communications;
- send commercial communications, where permitted;
- measure campaign effectiveness;
- improve customer relationship and user experience;
- document contractual, commercial or technical exchanges.
When you transmit to support files, screenshots, exports or messages containing personal data, such data is processed only to the extent necessary to handle the request, ensure security, resolve the incident or improve the service.
9. Purposes and Legal Bases
WYDIN SAS processes personal data only for specified, explicit and legitimate purposes.
The main purposes and legal bases are as follows:
Purpose
Data concerned
Legal basis
Account creation and management
account data, identity, contact, role, permissions
performance of the contract
Provision of the Orcheo service
account data, banking data, imported data, usage data
performance of the contract
Bank connections and integrations
banking, financial, technical and connection data
performance of the contract; consent or authorization where required
Subscription, invoice and payment management
identification, billing, payment, subscription data
performance of the contract; legal obligation
Customer support and incident handling
account data, messages, tickets, logs, attachments
performance of the contract; legitimate interest
Service security and fraud prevention
logs, IP, technical events, user actions
legitimate interest; legal obligation where applicable
Service improvement
usage data, feedback, aggregated or anonymized data
legitimate interest
Service-related communications
email, account, subscription, notifications
performance of the contract; legitimate interest
B2B commercial prospecting
identity, professional contact, company, marketing interactions
legitimate interest or consent where required
Audience measurement and analytics
cookies, page views, events, device
consent where required; legitimate interest for strictly necessary measurements
Compliance with legal obligations
invoices, accounting, rights requests, security
legal obligation
Dispute management
contractual data, exchanges, evidence, logs
legitimate interest
Where processing is based on WYDIN SAS’s legitimate interest, it is implemented only where it does not disproportionately affect the rights and freedoms of data subjects.
Where processing is based on consent, consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.
Where certain data is necessary for the performance of the contract, failure to provide it may prevent access to all or part of the Services.
10. Use of AI
Orcheo may use artificial intelligence, automation, statistical model or predictive analysis features in order to provide certain services to the Client.
These features may be used in particular to:
- categorize transactions;
- detect recurring transactions;
- identify anomalies, variations or trends;
- generate cash flow forecasts;
- produce summaries, explanations or analyses;
- suggest rules, categories or actions to be verified;
- assist with support, security or service improvement.
AI features may process certain Client Data, including banking, financial, usage or imported data, only to the extent necessary to provide the Services, ensure security, provide support or improve the service within the limits set out in this Policy.
AI-generated results are provided as analysis support. They may be incomplete, inaccurate or depend on the quality of the data used. They must be verified by the Client before any decision or use.
WYDIN SAS does not use Client Data to train, create or improve generic or non-customized artificial intelligence models, unless specifically agreed by the Client or where processing is carried out using aggregated, anonymized data or data that does not identify the Client, its Users or any data subject.
WYDIN SAS may use third-party artificial intelligence providers, including Anthropic Claude, Google Gemini or any equivalent provider. In such case, the data transmitted is limited to what is necessary for the relevant feature, and WYDIN SAS implements contractual and technical measures designed to protect the data processed.
The AI systems used by Orcheo are not intended to produce, on their own, decisions having legal or similarly significant effects on a person. The Client remains responsible for verifying the results and for making any decision with appropriate human validation.
Where the use of AI involves processing personal data, WYDIN SAS applies GDPR principles, including transparency, minimization, security, purpose limitation and respect for data subject rights.
11. Data Used / Not Used to Train Models
WYDIN SAS does not use Client Data to train, create or improve generic or non-customized artificial intelligence models, unless specifically agreed by the Client or unless otherwise expressly accepted by the Client.
Client Data may be processed by artificial intelligence features only to the extent necessary to provide the Services, in particular to categorize transactions, detect recurring transactions, identify anomalies, generate forecasts, produce analyses or assist the Client in using Orcheo.
WYDIN SAS may use aggregated, anonymized data or data that no longer reasonably identifies the Client, its Users or any data subject in order to measure, secure, improve, train, test or develop the Services, including their artificial intelligence features.
Data is considered anonymized only where it no longer reasonably allows a natural person to be identified directly or indirectly. Pseudonymization or aggregation does not necessarily constitute anonymization within the meaning of the GDPR.
Where third-party artificial intelligence providers are used, the data transmitted is limited to what is necessary for the relevant feature. WYDIN SAS implements contractual, technical and organizational measures designed to govern such processing and protect Client Data.
12. Recipients and Processors
Personal data processed by Orcheo may be accessed only by persons and entities that need to access it for the purposes described in this Policy.
Recipients may include in particular:
- authorized WYDIN SAS teams: product, technical, security, support, sales, billing, compliance;
- Users authorized by the Client within the Client Account;
- technical providers and processors necessary to provide the Services;
- banking, cloud, payment, analytics, email, support and artificial intelligence providers;
- WYDIN SAS’s professional advisers, including lawyers, accountants, statutory auditors or auditors;
- administrative, judicial, tax or regulatory authorities where required or permitted by law;
- purchasers, investors, auditors or advisers in connection with a financing, restructuring, merger, acquisition, asset transfer or similar transaction, subject to appropriate confidentiality obligations.
WYDIN SAS applies an authorization policy intended to limit access to data to authorized persons only and to data that is strictly necessary.
Where WYDIN SAS uses processors, it ensures that they provide sufficient guarantees in terms of confidentiality, security and personal data protection, and that they are subject to appropriate contractual obligations.
13. Banking, Cloud, Payment, Analytics and Support Providers
To provide Orcheo, WYDIN SAS may use various third-party providers, which may change over time.
These providers may be involved in particular for:
- cloud hosting and technical infrastructure;
- bank connection and access to financial data;
- payment, billing and subscription management;
- artificial intelligence and automated analysis;
- product and web analytics;
- transactional email;
- customer support and customer relationship management;
- security, monitoring, logs and maintenance.
As of the date of this Policy, the providers or categories of providers that may be used include in particular:
- Cloud hosting: Google Cloud;
- Bank connection / financial data: Powens, Plaid or equivalent providers;
- Payment / subscription: Stripe or equivalent provider;
- Artificial intelligence: Anthropic Claude, Google Gemini or equivalent providers;
- Product / web analytics: Google Analytics, HubSpot or equivalent providers;
- Transactional email: Postmark or equivalent provider;
- Support / CRM: HubSpot or equivalent provider.
This list is indicative and may be changed to take into account technical, commercial, regulatory or operational developments of Orcheo.
Where certain providers act as independent controllers, their own terms and privacy policies may also apply, in particular for certain banking, payment or analytics services.
14. Transfers Outside the European Union
WYDIN SAS gives priority, where possible, to hosting and processing data within the European Union or in countries benefiting from an adequacy decision recognized by the European Commission.
Certain personal data may, however, be transferred to or made accessible from outside the European Union, in particular where necessary to provide the Services, support, hosting, security, artificial intelligence, analytics, payment or to involve third-party providers.
Such transfers may concern, in particular, the United States, Canada or any other country in which a provider, affiliated entity or authorized team is involved in providing the Services.
Where data is transferred outside the European Union, WYDIN SAS implements the appropriate safeguards provided by the GDPR, including:
- an adequacy decision of the European Commission;
- standard contractual clauses of the European Commission;
- additional security measures where necessary;
- any other transfer mechanism recognized by applicable regulations.
The Client may contact WYDIN SAS to obtain further information on the safeguards applicable to international data transfers.
15. Retention Periods
WYDIN SAS retains personal data only for as long as necessary for the purposes for which it is processed, unless a longer legal retention obligation applies or retention is necessary for evidence, security or litigation purposes.
Indicative retention periods are as follows:
Data category
Indicative retention period
Active account data
Duration of the Subscription
Client Account data after termination
Up to 90 days in the active database, unless exported, deleted earlier or otherwise required
Billing and accounting data
10 years from the close of the relevant financial year
Payment data
Duration necessary for the transaction, then according to the periods imposed by the payment provider and legal obligations
Banking and financial data processed in Orcheo
Duration of the Subscription, then deletion or anonymization within a reasonable period after termination
Data imported by the Client
Duration of the Subscription, then deletion or anonymization within a reasonable period after termination
Security logs
Up to 12 months, unless incident, investigation, legal obligation or evidentiary need
Usage data and product analytics
Up to 25 months where linked to cookies or trackers, or a shorter period depending on applicable settings
Support data
Up to 5 years after closure of the ticket or request
Prospect and marketing data
Up to 3 years from the last active contact with Orcheo
Data relating to rights requests
Up to 5 years from closure of the request
Data necessary for dispute management
Duration of the dispute, then applicable limitation period
Data may be retained for longer in intermediate archives where necessary to comply with a legal obligation, establish evidence of a right or contract, prevent fraud, manage litigation or respond to a request from a competent authority.
Technical backups may contain certain data for a limited period, according to the applicable backup and deletion cycles. Such backups are used only for continuity, security, restoration or technical evidence purposes.
At the end of the applicable retention periods, data is deleted, anonymized or archived in accordance with applicable legal and technical requirements.
16. Security
WYDIN SAS implements appropriate technical and organizational measures to protect personal data processed in Orcheo against destruction, loss, alteration, unauthorized disclosure or unauthorized access.
These measures are intended in particular to preserve the confidentiality, integrity, availability and resilience of the website, application, systems and data.
They may include, as applicable:
- access control and authorization management;
- User authentication;
- secure passwords and, where applicable, enhanced authentication;
- encryption of communications;
- protection of data in transit and at rest where applicable;
- logging of access and events;
- technical monitoring and anomaly detection;
- backups and continuity measures;
- limitation of internal access to authorized persons only;
- measures to protect against unauthorized access, abuse, fraud and cyberattacks;
- incident management procedures;
- selection of providers offering appropriate security guarantees.
WYDIN SAS regularly improves its security measures to take into account the state of the art, risks, implementation costs, the nature of the data processed and the evolution of the Services.
The Client and Users also contribute to Orcheo’s security. In particular, they must protect their credentials, use strong passwords, not share their access, update their permissions and inform Orcheo without delay in the event of suspected compromise.
No IT system, network, cloud service or electronic transmission can be guaranteed to be completely secure. In the event of an incident affecting personal data, WYDIN SAS implements the measures required by applicable regulations and, where required, informs the relevant persons or authorities.
17. Data Subject Rights
Depending on the applicable regulations and the conditions set out therein, data subjects may have the following rights over their personal data:
- right of access;
- right to rectification;
- right to erasure;
- right to object;
- right to restriction of processing;
- right to data portability;
- right to withdraw consent where processing is based on consent;
- right to define instructions regarding the fate of their data after death, where applicable;
- right not to be subject to a decision based solely on automated processing producing legal effects or similarly significant effects, where applicable.
These rights may be exercised by contacting WYDIN SAS at:
privacy@orcheo.com
or by post:
WYDIN SAS
61 Rue Emeriau
75015 Paris
France
For security reasons, WYDIN SAS may request additional information to verify the requester’s identity where necessary.
WYDIN SAS responds to requests within the time limits provided by applicable regulations. Under the GDPR, this period is in principle one month from receipt of the request, unless an extension is possible where the request is complex or in the event of numerous requests.
Where WYDIN SAS acts as processor on behalf of a Client, requests relating to data integrated, imported or connected by that Client should in principle be addressed to the relevant Client, which acts as controller. WYDIN SAS may assist the Client in handling such requests in accordance with the Data Processing Agreement.
Data subjects may also lodge a complaint with the competent supervisory authority. In France, this is the CNIL.
18. Users Located in the European Union
Persons located in the European Union, the European Economic Area, the United Kingdom or Switzerland may benefit from the rights provided by applicable data protection regulations, including the GDPR where applicable.
These rights include in particular:
- access to personal data concerning them;
- rectification of inaccurate or incomplete data;
- erasure of data in the cases provided by law;
- restriction of processing;
- objection to processing, in particular where it is based on legitimate interest;
- portability of data provided, where the legal conditions are met;
- withdrawal of consent, where processing is based on consent;
- the right to lodge a complaint with a supervisory authority.
Where data is transferred outside the European Union, WYDIN SAS implements the appropriate safeguards provided by applicable regulations, including adequacy decisions, standard contractual clauses or additional measures where necessary.
Users located in the European Union may exercise their rights by contacting WYDIN SAS at the address indicated in this Policy.
19. Users Located in the United States
Certain U.S. data protection laws may apply to persons located in the United States, depending on their state of residence and the thresholds or conditions of application provided by such laws.
For California residents, where the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), applies, data subjects may in particular have the following rights:
- right to know which categories of personal data are collected, used, disclosed, sold or shared;
- right to access certain personal data;
- right to request deletion of certain personal data;
- right to request correction of inaccurate personal data;
- right to opt out of the sale or sharing of personal data, where applicable;
- right to limit the use and disclosure of certain sensitive data, where applicable;
- right not to be discriminated against for exercising such rights.
WYDIN SAS does not sell Users’ personal data in the ordinary meaning of the term. If certain tracking, analytics or advertising practices were to be considered “sharing” or “selling” within the meaning of an applicable U.S. law, WYDIN SAS would implement the required information and opt-out mechanisms.
Orcheo is designed as a B2B service for professionals. The data processed mainly concerns professional accounts, professional users and corporate financial data. However, certain data may be considered personal data within the meaning of applicable U.S. laws.
Users located in the United States may exercise their rights by contacting WYDIN SAS at the address indicated in this Policy. WYDIN SAS may request the information necessary to verify the requester’s identity and the applicability of the relevant law.
20. Users Located in Canada
Where applicable Canadian privacy legislation applies, including the Personal Information Protection and Electronic Documents Act (“PIPEDA”) or any applicable provincial law, WYDIN SAS processes personal information in accordance with the applicable principles of transparency, accountability, identified purposes, consent, limiting collection, limiting use, security and access.
Persons located in Canada may, depending on the applicable law, have the following rights in particular:
- to be informed of the purposes of the collection, use and disclosure of their personal information;
- to access personal information concerning them;
- to request correction of inaccurate or incomplete information;
- to withdraw consent where processing is based on consent, subject to applicable contractual or legal limits;
- to obtain information on the providers or categories of providers to whom information may be disclosed;
- to lodge a complaint with the competent authority, including the Office of the Privacy Commissioner of Canada where competent.
WYDIN SAS may process or transfer certain personal information outside Canada, including in the European Union, the United States or other countries where its providers are involved. In such case, the information may be subject to the laws of the relevant country. WYDIN SAS implements contractual, technical and organizational safeguards designed to protect such information.
Users located in Canada may exercise their rights by contacting WYDIN SAS at the address indicated in this Policy.
21. Cookies and Trackers
When browsing the Website or using the Application, cookies, trackers, pixels, SDKs, technical identifiers or similar technologies may be placed on or read from your device.
A cookie is a small file or identifier stored on your browser, device or application, enabling in particular your device to be recognized, certain information to be remembered, your session to be secured, audience measurement to be carried out or certain content to be personalized.
Orcheo may use several categories of cookies and trackers:
Strictly Necessary Cookies
These cookies are necessary for the operation of the Website or Application. They enable in particular:
- authentication;
- session security;
- storage of your essential preferences;
- cookie consent management;
- operation of forms;
- prevention of fraud or unauthorized access.
These cookies do not require your consent where they are strictly necessary for the service requested.
Functionality Cookies
These cookies make it possible to improve or personalize your experience, for example by remembering certain settings, display preferences, language, region or navigation choices.
Refusing them may limit certain non-essential features.
Audience Measurement and Analytics Cookies
These cookies make it possible to measure traffic on the Website or Application, understand the use of pages and features, detect errors, improve performance and optimize the user experience.
They may be placed by Orcheo or by providers such as Google Analytics, HubSpot or any equivalent provider.
Where they are not strictly necessary or exempt from consent, these cookies are subject to your prior consent.
Marketing or Advertising Cookies
These cookies may be used to measure the effectiveness of campaigns, personalize certain content, track marketing interactions or offer communications adapted to your professional profile.
They are placed only with your consent where consent is required.
Third-Party Service Cookies
Certain cookies may be placed by third-party services integrated into the Website or Application, including support, CRM, analytics, embedded content, video, security or communication tools.
Such third-party services may process certain data in accordance with their own privacy policies where applicable.
22. Cookie Consent Management
On your first visit to the Website, a banner or consent management tool allows you to accept, refuse or configure non-strictly necessary cookies.
You may modify or withdraw your consent at any time via the cookie management tool available on the Website or, where applicable, in the Application.
Refusing non-necessary cookies must be as simple as accepting them.
Refusing non-necessary cookies does not prevent access to the Website or Services, except for certain optional features that technically require the use of such cookies or trackers.
Consent or refusal choices may be retained for a maximum period of six months, unless a different period is justified by the context, applicable regulations or recommendations of the competent authority. After this period, your choice may be requested again.
You may also manage cookies through your browser settings. However, blocking certain strictly necessary cookies may degrade or prevent access to certain features of the Website or Application.
Where Orcheo offers consent management applicable across several devices or browsers, the user must be able to accept, refuse or withdraw consent with equivalent simplicity and scope.
23. Privacy Contact
For any question relating to this Policy, personal data processing carried out by Orcheo, cookies or the exercise of your rights, you may contact WYDIN SAS:
By email: privacy@orcheo.com
By post:
WYDIN SAS
61 Rue Emeriau
75015 Paris
France
In order to protect personal data, WYDIN SAS may request additional information to verify your identity where necessary, in particular in the event of reasonable doubt or a sensitive request.
Where your request concerns data processed by Orcheo on behalf of a Client, WYDIN SAS may invite you to contact the relevant Client directly, which acts as controller, or transmit your request to that Client where appropriate.
WYDIN SAS endeavors to respond to requests within the time limits provided by applicable regulations.
24. Complaint to the CNIL
If, after contacting us, you believe that your rights are not being respected or that the processing of your personal data does not comply with applicable regulations, you may lodge a complaint with the Commission nationale de l’informatique et des libertés.
The complaint may be filed online on the CNIL website or by post at the following address:
CNIL – Service des plaintes
3 Place de Fontenoy
TSA 80715
75334 Paris Cedex 07
France
The CNIL states that a complaint must in particular specify the organization concerned, the identity and contact details of the requester, and be accompanied by the elements useful for its examination.
