Skip to main content

Privacy policy

Summary:

 

  • Purpose of this Policy
  • Identity of Data Controllers and Data Processors
  • Definitions
  • Purposes and legal bases for processing
  • Data processed
  • Data subjects
  • Recipients of the data
  • Transfer of data outside the European Union
  • Data security
  • Data retention period
  • Implementation of specific processing operations: the Application
  • Rights and how to exercise them
  • Nature of the requirement to provide personal data


Purposes of this Policy

The CORUM Butler Group attaches great importance to the protection of your privacy and your personal data.
In this Privacy Policy, CORUM L’Épargne, CORUM Asset Management and CORUM Life constitute the CORUM Butler Group (“the Group”).
When you visit the websites corum.fr and corumbutler.com (hereinafter the “Sites”), or use the mobile app (hereinafter “the App”) available on Android and iOS, certain information may be collected. This information may include personal data relating to you (“Personal Data”). This Privacy Policy, together with the Cookie Policy, is provided to help you better understand our practices regarding the collection and processing of this personal data.

Identity of Data Controllers and Data Processors

CORUM L’Épargne SAS, 851 245 183 RCS Paris, Financial Investment Adviser (CIF) and General Insurance Agent (AGA), collects and processes Personal Data as a Data Controller in connection with the management of your subscriptions and contracts.
CORUM L’Épargne is the exclusive distributor of:
 

  • financial products managed by CORUM Asset Management;
  • policies and funds managed by CORUM Life.

Certain data collected by CORUM L’Épargne is subsequently processed by other entities within the Group, which then act as separate Data Controllers.
CORUM Asset Management SAS, 531 636 546 RCS Paris, a producer and manager of Real Estate Investment Trusts (SCPI), collects and processes Personal Data as a Data Controller in connection with the management of your subscriptions.
CORUM Life SA, 852 264 332 RCS Paris, a provider of insurance and fund products, collects and processes your Personal Data as a Data Controller in connection with the subscription to and management of your policies.
CORUM L’Épargne also operates an exclusive network of wealth management advisers, business introducers and brokers. The processing carried out by wealth management advisers, business introducers and brokers falls within the scope of their own activities in their capacity as separate Data Controllers.

Definitions

For the purposes of this Privacy Policy, if certain terms and expressions used are not defined in this section, they shall have the meaning given to them by the applicable regulations relating to the processing of Personal Data

.“Applicable Regulations relating to the processing of Personal Data”
means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”) and Law No. 78-17 of 6 January 1978, known as the “Data Protection Act”, as amended by Law No. 2018-493 of 20 June 2018 and Order No. 2018-1125 of 12 December 2018, as well as any laws, regulations or statutory provisions adopted pursuant to the foregoing. “Personal

Data”
means any information relating to an identified or identifiable Customer. A natural person is deemed to be “identifiable” if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to their physical, physiological, genetic, economic, cultural or social identity. “Data

Controller”
means the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing. “Joint Controllers” means entities that share personal data for their own distinct purposes, without any hierarchical relationship or mutual control over the processing carried out by each. Each entity decides independently on the purposes and means of the data processing it carries out.

“Processor”
means the natural or legal person who processes Personal Data on behalf of the Data Controller. “Data

Protection Officer (DPO)”
means the person appointed by the Group as responsible for the management of Personal Data. They are the driving force behind the Group’s ongoing and dynamic compliance framework and act as the Group’s representative in managing your requests to exercise your rights

.“Client”
refers to a natural person who has a contractual relationship with the Group.

A person may be a client of CORUM L’Épargne and, respectively, of CORUM Asset Management and/or CORUM Life, depending on the financial and/or insurance product in which they invest

.““““Prospect”
refers to a natural person who is not yet a client of the Group but who has expressed an interest in its products or services. This expression of interest may take various forms, such as a contact request, subscription to a newsletter, initiation of a subscription process, or any other interaction with the Group indicating the potential for a future commercial relationship.

Purposes and legal bases for processing

The Group carries out various processing activities, the legal bases and purposes of which are as follows:
 

  • the performance of pre-contractual and contractual measures enabling the pursuit of the following purposes:
  •  
    • the management of operations necessary in relation to the products or services you have subscribed to;
    • the analysis of data, in particular to personalise the products offered according to your profile;
    • the management of the Group’s commercial relationship with you.
  • your consent, enabling the following purposes to be pursued:
  •  
    • the management of cookies subject to consent;
    • sending personalised or non-personalised electronic communications relating to the Group’s products, services and news;
    • surveys and polls.
  • compliance with regulatory obligations, enabling the following purposes:
  •  
    • providing evidence of transactions carried out;
    • compliance with the duty to provide information and advice;
    • the management of the Group’s general accounts;
    • the management of insurance guarantees;
    • the management of anti-money laundering and counter-terrorist financing measures;
    • preventing and combating fraud;
    • the management of official requests from authorised supervisory authorities;
    • verifying the nature of the service provided and the content of information communicated to Clients and Prospects, in particular through the recording of telephone calls;
    • the provision of regulatory information and documents;
  • the legitimate interest in pursuing the following purposes:
  •  
    • responding to contact requests you send to the Group;
    • training staff through the recording of telephone calls;
    • the management of cookies not subject to consent (see cookie policy).


The purposes pursued on the basis of the Group’s legitimate interests are carried out in accordance with your rights and freedoms.
In any event, and for each defined purpose, the Group will use all means at its disposal to ensure the security and confidentiality of the Personal Data entrusted to it, in accordance with the laws and regulations in force.

Data processed

Unless otherwise stated, the data collected by the Group is necessary and mandatory for the performance of the contract or to comply with our regulatory obligations.
The following are recorded in particular:
 

  • your surname, first name and date of birth;
  • postal address, email address, telephone number and your login details;
  • your tax, family status, income and asset information;
  • information regarding your education and professional status;
  • your bank details.


Your data is collected either directly from you by the Group, or from our Partners or our Customers (particularly in the context of referrals). None of your data is collected by the Group from publicly available sources.

Data subjects

The data subjects concerned by the processing are:
 

  • Prospects who contact the Group to obtain information about the products and services offered;
  • the Group’s Customers;
  • any user of this website.

Recipients of the data
For the purposes described above, and solely for these purposes, the data collected may be disclosed to all or some of the following recipients:
 

  • the Group’s employees;
  • the Group’s contractual partners and subcontractors;
  • the relevant regulatory and supervisory authorities.

The Group may transfer Personal Data to its entities if such transfer is necessary for the purposes mentioned above.
The Group takes appropriate and reasonable measures to ensure that only employees with a legitimate need to access Personal Data may do so.

Transfer of data outside the European Union

The data collected and processed by the Group is hosted in France or within the European Union.
Certain Personal Data may nevertheless be transferred outside the European Union in connection with the use of a Sub-Contractor. Where applicable, the Group implements the necessary measures to secure such transfers. For example:
 

  • by ensuring that the transfer takes place to a country that has been the subject of an adequacy decision by the European Commission;
  • by ensuring that the transfer constitutes one of the exemptions provided for in Article 49(1) of the GDPR;
  • by implementing the European Commission’s standard contractual clauses.

You may obtain a copy of the existing measures by submitting a request to the Data Protection Officer (DPO):
 


CORUM Butler
Data Protection Officer
1, rue Euler – 75008 Paris Data

security

The Group implements all necessary physical, technical and organisational measures to ensure the confidentiality, integrity and availability of Personal Data. Restricted access measures have been put in place, ensuring that your Personal Data is accessible only to authorised staff who are aware of data protection issues and undergo mandatory and ongoing training.
In the event of a Personal Data breach posing a risk to your rights and freedoms, the Group will notify the CNIL of this incident within the statutory timeframe. If this breach poses a high risk to your rights and freedoms, the Group will inform you as soon as possible of the nature of the incident and the measures taken to remedy it.
The Group carefully selects the partners and sub-processors who may be required to process your Personal Data, ensuring they comply with their current regulatory obligations regarding the security of Personal Data. Data

retention

period The retention period for your Personal Data varies. It is determined by the following criteria:
 

  • the purpose for which the Personal Data is processed; it is retained for as long as necessary for that purpose;
  • the duration and nature of your relationship with the Group;
  • the applicable legal and regulatory obligations, which may set a minimum retention period for personal data.

Purposes Retention
periods
If you are a Customer, the management of our commercial relationship with you Contract
management (excluding life insurance):
 

  • Active database: duration of the contractual relationship
  • Archiving: five (5) years

 
Management of life insurance contracts:
 

  • Active database: until the death of the insured
  • Archiving: thirty (30) years from the death of the insured

 Customer relationship
management (satisfaction, complaints, after-sales service):
 

  • Active database: duration of the contract
  • Archiving: five (5) years

 
Pre-contractual checks and legal declarations:
 

  • Active database: for the duration of the procedure
  • Archiving: five (5) years from the end of the contract

 
Sales statistics:
 

  • Active database: for the time necessary to fulfil the purpose of the statistics, or until the right to object is exercised

 
Retention of data used for marketing purposes:
 

  • Three (3) years from the customer’s last action (reply to an email, click on a hyperlink, login to the customer portal, etc.)

If you are a Prospect, the management of our commercial relationship with you
Retention of data used for marketing purposes:
 

  • Prospects: three (3) years from the prospect’s last action (reply to an email, click on a hyperlink, etc.)


Management of our general accounts

Retention of data required for tax purposes (invoices): the current financial year, plus ten (10) years from the end of
the financial year Management of anti-money laundering and counter-terrorist financing
measures The entire duration of the contractual relationship, followed by five (5) years from the end of the contract.

Management of official requests from authorised supervisory
authorities Retention of data to meet the requirements of the authorities (CNIL, AMF, ACPR): until the conclusion of the relevant procedure, then for five (5) years following the conclusion of the relevant procedure.

Submission of reports to supervisory authorities
Retention of reports for five (5) years.

Establishing proof of transactions carried out:
For the entire duration of the contractual relationship, then five (5) years from the end of the contract.

Recording and transcribing telephone conversations to facilitate the verification of the regularity of operations carried out and their compliance with the instructions of the principals:
The retention period for recordings is five (5) years from the call.
Transcripts are retained for twelve (12) months from the date of the call.

Management of complaint files
: Five (5) years from the date of collection or the last contact from the Prospect

. Management of requests to exercise rights
: Requests to exercise rights are retained for five (5) years from the end of the calendar year in which the request was made.
Responses to contact requests you send us
Retention of requests (other than requests to exercise rights):
 

  • In the active database: three (3) years after the last contact
  • In the intermediate archive: five (5) years (limitation period)


Implementation of specific processing operations: the App
When you use the App, CORUM L’Épargne collects the same data as that collected via the corum.fr website and for the same purposes as those defined for the corum.fr website.
In addition to these purposes, when you use the App, CORUM L’Épargne requests specific access permissions from you.
These permissions allow CORUM L’Épargne to access certain resources stored on your device, namely:
Permission requested

Purpose Biometric identification
feature(s) provided and managed by your mobile device (This permission is optional and allows us to identify you with certainty)Mobile device notificationsThis permission is optional and enables you to receive all our news in

real time. Access to these features is granted solely for the purpose of providing the services within the App that you choose to use, the terms of use for which are governed by your mobile device.
Rights and how to exercise them
In accordance with Article 13(2)(b) of the GDPR, any data subject is informed of the rights they may exercise at any time with the Group:
Rights

Further information

Right of access You have the right to request, free of charge, a copy of your personal data held (directly or indirectly). However, if this request is deemed unreasonable or excessive, the Group reserves the right to charge a fee to respond to this request for access. Right to object You have the right to object at any time to the processing of your Personal Data in relation to commercial communications by email or telephone, including offers and news about our products. You also have the right to withdraw your consent to direct marketing at any time.
In the context of managing your contract, the right to object does not apply, in accordance with legal and regulatory obligations.
Right to rectification You have the right to request that the Group updates or corrects your personal data. Right to erasure Prospects and Customers who no longer have a contractual relationship with the Group, beyond the statutory and regulatory retention periods, may request the deletion of their personal data.Right to restriction of processing You have the right to request the restriction of the processing of your personal data if you believe that the information held by the Group is incorrect or if you consider its use to be unlawful. If this right is exercised legitimately, the Group will suspend all processing of your personal data until the issue is resolved. Right to data portability You have the right to request a copy of your personal data from the Group in a structured, commonly used and machine-readable format. Furthermore, you may request that your personal data be transferred to another data controller, if this is technically feasible. This right applies under the following conditions:
(1) The Group processes your personal data with your consent or the processing is necessary for the performance of a contract concluded with you – and;
(2) The processing is carried out by automated means.
To exercise these rights, you may contact the Data Protection Officer (DPO):
 

CORUM Butler
Data Protection Officer
1, rue Euler – 75008 Paris

If, after contacting the Group’s DPO, you feel that your data rights have not been respected, you may lodge a complaint with the CNIL (CNIL complaint) via the CNIL website using the online complaint service, or by post by writing to: CNIL – Complaints Department – 3 Place de Fontenoy – TSA 80715 – 75334 PARIS CEDEX 07.
Under the provisions of Law No. 2014-344 of 17 March 2014 on consumer affairs, you may refuse to be contacted for marketing purposes and register on the website www.bloctel.gouv.fr, the BLOCTEL service for opting out of telemarketing, which is 100% free of charge.
The Group undertakes to ensure that the collection and processing of personal data, carried out via the Websites or the App, contractual documents, digital subscription processes or any other means, comply with the GDPR and the French Data Protection Act.
Nature of the requirement to provide personal data
The provision of Personal Data is of a regulatory or contractual nature for the purposes listed, corresponding to the performance of pre-contractual and contractual measures, as well as for purposes relating to compliance with regulatory obligations. In such cases, if you request the erasure of Personal Data or refuse to provide the data, you will no longer be able to enter into or continue the performance of the contract.