1. Who we are
- Company
- TOORE, Société par actions simplifiée (SAS)
- Registered office
- 5 Rue des Hautes Berges, 92160 Antony, France
- Registration
- RCS Nanterre 934 371 303
- Intra-EU VAT
- FR64934371303
- Publication director
- Thibault Geoffray, CEO
- Contact for privacy matters
- contact@toore.io
References to "Toore", "we", "us" or "our" mean that company.
2. The two roles we play
Toore handles personal data in two distinct capacities, and the rules differ depending on which applies.
As controller. For data collected through the toore.io website, through our commercial activity (prospects, demo requests, event contacts, newsletter recipients), through recruitment, and for the account and log data generated when someone uses the platform. Here we decide why and how the data is processed, and this policy governs it in full.
As processor. For the operational data a client organisation connects to the platform: feedstock and purchase records, product and diagnostic data, shop-floor execution data, pricing inputs, and any personal data contained in them. Here the client organisation is the controller. It decides the purposes and the means, and we act only on its documented written instructions, under the data processing terms annexed to its Accord Cadre.
If you are an employee of a Toore client and want to exercise rights over data held in the platform, address your request to your own organisation. We will assist it in responding, but we cannot act on that data on our own initiative. Sections 4, 8 and 11 below describe our controller processing; where we act as processor, the client's own privacy notice applies.
3. Data we collect
Data you give us. Your name, professional email address, phone number, employer, role, and the content of your messages when you contact us, request a demo, subscribe to our communications, or apply for a role. When an account is created for you on the platform, your identification details and access rights.
Data generated by your use. When you visit the website or use the platform, our servers record technical information: IP address, browser type and version, operating system, pages visited, time and date of each visit, referring page, and diagnostic data used to operate and secure the service. On the platform, we also log actions performed, for traceability and security.
Data we receive from others. Where a colleague refers you, where you interact with us on a professional network, or where we obtain professional contact details from public sources or business data providers for prospecting purposes.
Client operational data. The data a client organisation connects to the platform, described in section 2. This is largely industrial and commercial data rather than personal data, but it can contain personal data, typically the identity of the operators, buyers or planners who recorded an entry or made a decision.
We do not knowingly collect special category data (health, religious or philosophical beliefs, trade union membership, political opinions, biometric or genetic data, sexual orientation). Please do not send it to us.
4. Why we process it, and on what legal basis
We process personal data only where we have a legal basis to do so.
| Purpose | Data | Legal basis |
|---|---|---|
| Operating and securing the website | Log and technical data | Legitimate interest in running and protecting our site |
| Responding to your enquiries and demo requests | Identification and contact data, message content | Pre-contractual measures at your request |
| Providing, operating and maintaining the platform | Account, access and log data | Performance of the contract with your organisation |
| Support, maintenance and administrative communication | Contact and account data, incident content | Performance of the contract |
| Commercial prospecting with professional contacts | Professional contact data | Legitimate interest in developing our business, with a right to object at any time |
| Newsletters and marketing communications | Contact data | Consent, withdrawable at any time |
| Audience measurement and improving the site and product | Usage and technical data | Consent where cookies require it, otherwise legitimate interest |
| Recruitment | Application data | Pre-contractual measures at your request |
| Invoicing, accounting and debt recovery | Identification and transaction data | Legal obligation, and legitimate interest in recovering sums due |
| Establishing, exercising or defending legal claims | As relevant to the claim | Legitimate interest in defending our rights |
Where processing rests on our legitimate interest, we have balanced that interest against your rights and freedoms, and you may object under section 11.
Where processing rests on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before it.
5. Cookies and similar technologies
We use cookies and similar technologies on toore.io to operate the site, remember your preferences, and measure audience and performance.
Strictly necessary cookies are set without your consent, because the site cannot function without them. All others, including audience measurement and any advertising or social media cookies, are set only if you accept them through the banner presented on your first visit. You can change your choice at any time through the cookie settings link in the site footer, or through your browser settings. Refusing non-essential cookies does not prevent you from using the site, though some features may work less well.
| Category | Purpose | Consent | Retention |
|---|---|---|---|
| Strictly necessary | Session, security, load balancing, recording your cookie choice | Not required | Session duration |
| Audience measurement | Understanding how the site is used and improving it | Required | Maximum 13 months |
Consent choices are kept for a maximum of six months, after which the banner is presented again.
6. Who we share data with
We do not sell personal data.
We share it with service providers who process it on our behalf, under contracts imposing equivalent protection obligations, and only to the extent needed to run the service:
| Provider | Role | Location |
|---|---|---|
| Google Cloud | Hosting and infrastructure | European Union |
| Other service providers | CRM, analytics, support and internal communication | European Union or adequate safeguards |
Client operational data connected to the platform is hosted exclusively on servers located in the European Union. We do not host it outside the European Union.
We may also disclose personal data where required by law or by a competent authority, to protect our rights, or in connection with a corporate transaction such as a merger or acquisition, in which case the recipient is bound by this policy for the data transferred.
Where we engage a new subcontractor to process data on behalf of a client organisation, we inform that organisation in writing beforehand, stating the processing concerned and the subcontractor's identity, as set out in the data processing terms annexed to its Accord Cadre.
7. International transfers
We prioritise providers established in the European Union. Where a transfer outside the European Economic Area is unavoidable, we rely on an adequacy decision of the European Commission or on the European Commission's standard contractual clauses, together with any additional measures required, so that the data continues to benefit from an equivalent level of protection.
For personal data processed on behalf of a client organisation, we do not transfer data outside the European Union, or to a country not recognised as offering adequate protection, without that organisation's prior written agreement.
You may request a copy of the safeguards applied by writing to us.
8. How long we keep data
We keep personal data only for as long as necessary for the purposes described above, then delete or anonymise it.
| Data | Retention |
|---|---|
| Prospect and commercial contact data | 3 years from the last contact with you |
| Client account and contact data | Duration of the contract, then 5 years |
| Platform log and traceability data | 12 months |
| Website server logs | 12 months |
| Audience measurement data | Maximum 25 months |
| Cookie consent records | 6 months |
| Unsuccessful applications | 2 years from the last contact, unless you ask us to delete them sooner |
| Invoices and accounting records | 10 years, as required by the French Code de commerce |
| Evidence relating to a claim or dispute | Duration of the applicable limitation period |
Client operational data is retained for the duration of the client's use of the platform. At the end of the contract it is returned and our copies destroyed, under the reversibility terms of the Accord Cadre.
9. Security
We apply technical and organisational measures designed to protect personal data against loss, theft, and unauthorised access, disclosure, copying, use or modification. These include access controls limiting access to authorised staff on a need-to-know basis, confidentiality obligations on our personnel and subcontractors, encryption in transit, logging and traceability of actions, and a double backup with a daily backup and a 15-day history.
No method of transmission or storage is entirely secure, and we cannot guarantee absolute security. You are responsible for keeping your access credentials confidential, and should tell us without delay if you believe they have been compromised.
Where a personal data breach occurs, we notify the CNIL and, where required, the individuals concerned, within the time limits set by the GDPR. Where the breach affects data we process on behalf of a client organisation, we notify that organisation as soon as possible after becoming aware of it.
10. Automated decisions and profiling
Toore uses artificial intelligence to analyse feedstock, product and shop-floor data and to generate purchase, routing and dismantling recommendations.
These recommendations are decision support. A person, whether buyer, planner or operator, or the client organisation itself, remains in control of every commercial and operational decision. No decision producing legal effects concerning you, or similarly significantly affecting you, is taken solely by automated means.
Where automated processing of your personal data does occur, you may request human intervention, express your point of view and contest the outcome.
11. Your rights
Subject to applicable law, you have the following rights over personal data we hold about you as controller.
Access. You may ask whether we process data about you and obtain a copy of it, together with information on the purposes, recipients and retention periods.
Rectification. You may ask us to correct inaccurate data and complete incomplete data.
Erasure. You may ask us to delete data where it is no longer necessary for the purposes for which it was collected, where you withdraw the consent it rests on, where you object and there is no overriding legitimate ground, or where it has been processed unlawfully. We may retain data where required to meet a legal obligation or to establish, exercise or defend legal claims.
Restriction. You may ask us to restrict processing, for example while the accuracy of the data or the lawfulness of the processing is being verified. Restricted data is stored but not otherwise used without your consent, except as permitted by law.
Portability. Where processing rests on your consent or on a contract and is carried out by automated means, you may ask to receive the data you provided in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
Objection. You may object, on grounds relating to your particular situation, to processing carried out on the basis of our legitimate interests. Where we process data for direct marketing, you may object at any time and we will stop.
Withdrawal of consent. Where processing rests on consent, you may withdraw it at any time, without affecting processing already carried out.
Post-mortem directives. Under article 85 of the loi Informatique et Libertés, you may give directives on the retention, erasure and communication of your data after your death, and designate a person to carry them out.
Where you provide us with personal data relating to other people, for example colleagues you name in a message, you confirm you are entitled to do so and that they have been informed.
12. Exercising your rights
Write to us at contact@toore.io, or by post at the address in section 1.
We respond within one month of receiving your request. That period may be extended by two further months where the request is complex or where we receive a large number of requests, in which case we tell you within the first month and explain why.
We may ask you for information to confirm your identity where we have reasonable doubt about who is making the request. We will not use that information for any other purpose.
13. Complaints
If you are not satisfied with how we handle your data, you may lodge a complaint with the French supervisory authority:
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
cnil.fr
We would rather hear from you first, so please do contact us before or alongside any complaint.
14. Children's privacy
The platform is a professional tool intended for business users. Neither it nor the website is directed at children, and we do not knowingly collect personal data relating to children. If you believe a child has provided us with personal data, contact us so we can remove it.
15. External links
The website and the platform may contain links to sites we do not operate. We have no control over, and are not responsible for, the content or the privacy practices of those sites, and this policy does not apply to them.
16. Changes to this policy
We may update this policy to reflect changes in our practices or for legal reasons. The version in force is the one published on this page, identified by the "Last updated" date above. Where a change is significant, we will inform you by appropriate means before it takes effect.
17. Contact
For any question about this policy or about how we handle personal data: