🔥 HERO raises €11.3 million from US investment fund Valar - Find out more! 🔥

🔥 HERO raises €11.3 million from US investment fund Valar - Find out more! 🔥

Introduction

At Hero, we believe that managing one's own personal data is an important right for each and every one of our users. The purpose of this document is therefore to inform you about the collection and processing of your personal data by our company, in simple and understandable terms. Should you have any questions or complaints, please do not hesitate to contact our support team at the following address support@hero.fr or directly to our Data Protection Officer, at the following address dpo@hero.fr . To make it easier for you to read this document, we have divided it into different sub-sections, each dealing with a particular subject and describing as best we can how we manage your data.

Who is responsible for processing your personal data?

Our company, Coruscant SASU, registered in the Paris B Trade and Companies Register under number 899 485 544, is the party responsible for processing your personal data, in accordance with the RGPD (General Data Protection Regulation).

What types of personal data are collected and processed?

To make this document easier to read, each type of data is associated with the exact names of the data concerned. The legal basis is systematically based on the General Data Protection Regulation. Each of the data listed below is systematically collected.

DATA CONCERNED
Business name, legal name, national identification number (SIRET / SIREN), delivery address, billing address

LEGAL BASIS
Explicit user consent

PURPOSE OF PROCESSING
To enable the user to use the payment solution offered by Hero

RECIPIENT OF THE DATA COLLECTED, EXTERNAL TO HERO
Third-party anti-fraud and financial risk management services, likely to return a customer credit rating

Contact and identification details of the natural person

DATA CONCERNED
Last name, first name, email, telephone

LEGAL BASIS
Explicit user consent

PURPOSE OF PROCESSING
To enable the user to use the payment solution offered by Hero

Technical data about your computer or Internet connection

DATA CONCERNED
IP address, technical characteristics of the device used (OS, browser language, keyboard language, etc.), cookie

LEGAL BASIS
Hero's legitimate interests

PURPOSE OF PROCESSING
Ensure the security of payments managed by Hero and combat fraud

RECIPIENT OF THE DATA COLLECTED, EXTERNAL TO HERO
- Third-party anti-fraud services, which may analyze the data and return a bank fraud risk rating.

Information about your creditworthiness

DATA CONCERNED
Credit ratings from third-party rating agencies, bank statements, etc.

LEGAL BASIS
Hero's legitimate interests

PURPOSE OF PROCESSING
Ensure the security of payments managed by Hero and combat fraud

Payment data

DATA CONCERNED
Credit card number, expiry date and visual cryptogram

LEGAL BASIS
Explicit user consent

PURPOSE OF PROCESSING
To enable the user to use the payment solution offered by Hero

RECIPIENT OF THE DATA COLLECTED, EXTERNAL TO HERO
Payment providers used to debit the credit card

Hero user history

DATA CONCERNED
E-mail, telephone or postal exchanges with our teams

LEGAL BASIS
Hero's legitimate interests

PURPOSE OF PROCESSING
Ensure the security of payments managed by Hero and combat fraud - Provide a support service that is as responsive as possible to user requests

What are your rights regarding your personal data?

Hosting provider : Amazon Web Services EMEA SARL (38 AV JOHN F KENNEDY L 1855 99137 LUXEMBOURG).

In accordance with current regulations, you have the right to consult, modify, delete or transfer all data collected and processed by Hero. You may also choose to restrict our processing of your data, object to our processing or request a human review following automated processing of your data. Finally, you may withdraw your consent, decide to have your data processed post-mortem or lodge a complaint with the competent authority (the CNIL). To exercise one or more of these rights, please contact our Data Protection Officer at the following address dpo@hero.fr

In accordance with regulations, you are entitled to request any modification or deletion of all or part of the personal data already collected by Hero. In the event of such a request, you will be required to send any document confirming your identity (in particular an identity document such as a passport or national identity card). In this case, your request will be free of charge and Hero will reply within a reasonable time. To make such a request, please contact our Data Protection Officer at the following address dpo@hero.fr or support@hero.fr indicating all the necessary data. You are also entitled to contact the CNIL, whose contact details are displayed on their website. site internet .

What are our automatic profiling and decision-making mechanisms?

As part of its payment activity, Hero may use one or more profiling and automatic decision-making mechanisms. These decisions, which do not involve any sensitive data within the meaning of the General Data Protection Regulation, may impact the user by preventing him/her from finalizing a transaction. This may happen if the algorithm used assesses the risk of fraud, money laundering or default as being statistically too high. The algorithm will systematically use all the data at its disposal, obtained directly or indirectly from the user or from other external service providers (in particular credit rating agencies), in order to make the decision that safeguards the interests of the user and Hero. The user may, regardless of the situation and the decision of this automatic decision-making process, request a review of the decision by a Hero employee and provide his or her point of view as well as additional information. Hero undertakes to take into account all the elements that may enable it to revise its automatic decision before making its final decision.

Where do we process your personal data?

All your personal data is processed within the European Union.

How long do we store your personal data?

From the date of the last payment made by the user, Hero retains all data collected for a period of 5 years. This period corresponds to the legal period imposed by anti-money laundering and anti-terrorist financing regulations, with which Hero complies (in accordance with article L561-12 of the CMF).

How do we use cookies?

In order to ensure the security of its payments, Hero may use cookie technology as part of its legitimate interests. In particular, this cookie makes it possible to identify a device that has connected to the site's pages. hero.fr Hero does not use any other cookies.

Updates to this privacy statement

This privacy statement was updated on 30/08/2021.

Our contact details

Coruscant SASU, 231 rue Saint Honoré, 75001, Paris. support@hero.fr or dpo@hero.fr for all email contacts.