Date personale – Combaterea fraudei

Informațiile referitoare la tranzacția dvs. fac obiectul unei prelucrări automatizate a datelor de către Oneytrust, operatorul de date, cu scopul de a consolida nivelul de securitate al tranzacțiilor înregistrate de partener și de a proteja partenerul și clienții săi împotriva unei posibile furturi de identitate sau tentative de fraudă.

Transactions carried out online or in a physical shop using a payment method that presents a risk of fraud similar to an online transaction require a sufficient level of trust to exist between the contracting parties. Oneytrust helps to assess this level of trust by providing a decision-making tool. The aim of this service is to ensure that the identity used in the transaction is genuine by minimising checks in order to simplify and speed up consideration of your request. In the event of proven fraud, this service may result in your inclusion in a file of persons at risk (watch list).


Your data is used by Oneytrust exclusively for the purposes of the aforementioned service, for which all detailed information is provided in this document. In the event of suspected fraud following the first stage of verification, this data may be subject to additional checks by Oneytrust, where appropriate with the support of its service providers, so as to avoid, as far as possible, the implementation of additional checks such as the verification of your proof of identity and address. The reliability of the data that you have transmitted for the purposes of the operation may in this context be checked by cross-referencing your data with that of Oneytrust or its service providers.

Obiectul prelucrării datelor

Scopuri

Scopul prelucrării datelor puse în aplicare de Oneytrust este de a combate frauda de identitate și de plată/restituire în cazul tranzacțiilor efectuate la distanță prin internet sau într-un magazin fizic cu o metodă de plată care prezintă un risc de fraudă similar unei tranzacții online.
Aceasta permite Oneytrust :

  • analyse the data from the operation;
  • deliver a progressive assessment at different stages of the customer’s journey on the partner’s site(s), in order to guide the end customer’s subsequent journey accordingly;
  • provide an initial level of confidence, in particular by comparing the information on the transaction analysed with the information contained in the transactions carried out with Oneytrust’s various partners, thus detecting any inconsistencies based on pre-established rules, and assigning an evaluation (score) to each transaction carried out on the partner platforms; once the transaction has been validated by the customer and sent for analysis, provide the partner with a confidence index for the transaction in the form of a score between zero (0) and one hundred (100) depending on the level of risk assessed;
  • to determine, if the person concerned has consented, the machine identifier of the terminal (computer, smartphone, tablet, etc.) used by the said person to browse the partner’s site(s), in particular to check that the same terminal has not been used to carry out several transactions on the basis of different identities;
  • retrieve additional information from Oneytrust’s service providers to enrich and qualify certain transaction data (e-mail address, telephone, postal address, IP address, BIN 6);
  • în conformitate cu reguli prestabilite, pentru a reduce revizuirile manuale prin validarea automată a tranzacțiilor care nu au putut fi validate de un dispozitiv de analiză automată (scor automat);
  • detect attempted fraud when transactions are carried out via the Internet or in a physical shop using a payment method that presents a similar risk of fraud to an online transaction, and register customers who have committed proven fraud on a file of people at risk (watch list);
  • to carry out research or experimental phases in order to improve and enhance its solutions so that they are ever more relevant and appropriate, in order to protect consumers by continually improving the system for combating fraud; to this end, the data may be reused to train AI models.

Datele dumneavoastră pot fi adnotate (li se pot atribui una sau mai multe caracteristici) de către Oneytrust pentru a identifica categoriile de date din setul de date.


Any irregular declaration or anomaly may result in the registration of the data relating to the transaction associated with this irregular declaration or anomaly on a watch list set up by Oneytrust.

Baza legală

Articolul 6 (1) f din regulamentul general privind protecția datelor.
The processing is necessary for the purposes of the legitimate interests pursued by Oneytrust; namely, the fight against identity and payment fraud during remote transactions carried out via the Internet or in a physical shop with a payment method presenting a risk of fraud similar to an online transaction.


The collection of information from the terminal used to determine the machine identifier is a function of the Oneytrust service which requires the consent of the person concerned (article 82 of the amended law of 6 January 1978).

Date prelucrate

Categorii de date prelucrate

  • Identification data: title, surname, first name, date of birth, e-mail address, postal address, telephone number, fax number, customer ID, NIF depending on the country of the transaction, proof of identity or K-bis extract, proof of address.
  • Economic and financial information: Bank card number (PAN) hashed, expiry date, first 6 and/or last 4 digits of bank card, IBAN, RIB, proof of income.
  • Connection data: IP address, fingerprint calculated from the technical data of the terminal used (operating system, language, resolution, browser type and version, etc.).
  • Transaction data: Delivery method, payment method, name of carrier, address of collection point or other delivery location, transaction reference amount and currency, date and time of transaction, number of products purchased, list of products, quantity per product, unit price of product, number of purchases, cumulative amount of purchases, date and time of first and last order.
  • Other categories of data: Confidence index, technical sub-elements for validating identification data, IP address and BIN6 by correlation (validity, associated identity, supplier, operator, etc.).

Sursa datelor

Informațiile sunt colectate de la persoana în cauză prin intermediul partenerului, dar și de la furnizorii de servicii ai Oneytrust pentru date suplimentare și din baze de date accesibile publicului.

Caracterul obligatoriu al culegerii datelor

Netransmiterea datelor referitoare la operațiunea dumneavoastră împiedică Oneytrust să le analizeze. Executarea operațiunii dumneavoastră este la discreția exclusivă a partenerului Oneytrust.

You may refuse to give your consent to the collection of data used to calculate your terminal’s machine identifier and continue browsing. Terminal data is not collected in the absence of your consent, and this has no impact on browsing and the completion of the planned transaction.

Proces decizional automatizat

The solution offered by Oneytrust to its partners is a decision-making tool that determines a level of confidence linked to the transactions recorded by the partner. The system has been developed to allow manual analyses to be carried out if necessary when the confidence index is drawn up, based on the automated data processing implemented by Oneytrust. Whatever the recommendation issued by Oneytrust, the partner is the sole decision-maker as to the follow-up to be given to the operation. Oneytrust does not intervene in the partner’s final decision.

The processing implemented by Oneytrust does not provide for refusal decisions based exclusively on automated analysis. In the event of a refusal decision being taken by the partner, based solely on Oneytrust’s recommendations, the data subject has the right to ask Oneytrust for human intervention, to make observations and to request a re-examination of his or her situation with regard to the processing carried out by Oneytrust.

Persoane vizate

Prelucrarea datelor vizează:

  • persoanele fizice și juridice care efectuează tranzacții la punctele de vânzare fizice și la distanță, cu partenerii Oneytrust;
  • personalul autorizat al Oneytrust responsabil cu realizarea prelucrării.

Destinatarii datelor

Categorii de destinatari

În funcție de nevoile lor respective, sunt destinatari ai datelor în totalitate sau în parte:

  • personalul autorizat al Oneytrust ;
  • partenerul Oneytrust cu care clientul a efectuat operațiunea; acesta din urmă primește în special rezultatele prelucrării efectuate de Oneytrust, în conformitate cu prezentul document.
  • subcontractanții și furnizorii de servicii ai Oneytrust; în special, cei cărora Oneytrust le trimite toate sau o parte din date pentru verificare, găzduire și furnizarea de date suplimentare. Fiind de la sine înțeles că acești furnizori de servicii sunt obligați prin contract să protejeze datele cu caracter personal care le sunt transmise în acest context.

Transferurile de date în afara UE

Your data is stored within the European Union.

Oneytrust may use service providers located outside the European Union who may remotely access the data for specific services. These transfers may only be carried out after Oneytrust has taken the appropriate security measures, for example by ensuring the conclusion of standard clauses defined by the European Commission in order to control data flows.

In order to determine the machine identifier of the terminal used to browse the partner’s site(s), Oneytrust uses a service provider located in the USA who can remotely access the data collected associated with your terminal. The transfer of data is governed by the European Commission’s Standard Contractual Clauses and by additional measures to ensure effective data protection during the transfer.

On request, we can provide you with the names of recipients established outside the European Union and a copy of the specific conditions agreed in order to guarantee an appropriate level of data protection. If you wish to make such a request, please write to the Oneytrust DPO, whose contact details are given below.

Durata de păstrare a datelor

The data is kept for a period of :

  • 37 months;
  • 15 months for supporting documents and the footprint calculated from the terminal’s technical data;
  • 6 months for consumption data.

Data relating to transactions for which fraud has been detected is entered on a watch list for a period of 2 years or until the payment incident is rectified if this occurs before the 2-year period expires.

The technical sub-elements used to validate the identification data, IP address and BIN6 (validity, associated identity, supplier, operator, etc.) will be kept for a period of 15 days.

Drepturile dumneavoastră asupra datelor care vă privesc

În conformitate cu regulamentele aplicabile, vă puteți exercita drepturile prevăzute mai jos:

  • Dreptul de acces pentru a obține o copie a tuturor datelor prelucrate de Oneytrust, precum și informații referitoare la caracteristicile prelucrării efectuate asupra datelor dumneavoastră.
  • Dreptul de rectificare pentru a vă actualiza datele eronate și/sau incomplete.
  • Dreptul la ștergere dacă datele (i) nu mai sunt necesare în scopurile pentru care au fost colectate, (ii) sunt prelucrate ilegal sau (iii) dacă vă exercitați dreptul de a vă opune prelucrării în cauză. Cu toate acestea, acest drept nu se aplică în cazul în care păstrarea datelor dvs. este necesară pentru ca Oneytrust să respecte o obligație legală sau pentru exercitarea creanțelor legale.
  • Right to restrict processing where (i) you dispute the accuracy of the data, (ii) you exercise your right to object. Oneytrust will restrict the processing of your data for such time as is necessary for Oneytrust to carry out appropriate checks.
  • Dreptul de a vă opune ca datele dumneavoastră să fie utilizate de Oneytrust pentru interesele sale legitime. Oneytrust va înceta atunci această prelucrare, cu excepția cazului în care poate justifica că interesele sale legitime și prioritare prevalează asupra drepturilor și libertăților dumneavoastră.
  • Dreptul de a defini directive generale și specifice care să stabilească modul în care doriți ca drepturile de mai sus să fie exercitate după decesul dumneavoastră.

Exercitarea drepturilor dumneavoastră

Responsabilul cu protecția datelor (DPO) de la Oneytrust este interlocutorul dumneavoastră pentru orice cerere de exercitare a drepturilor dumneavoastră legate de această prelucrare.

  • Contactați DPO pe cale electronică scriind la dpo[at]oneytrust.com* *(înlocuiți [at] cu @ când trimiteți e-mailul)
  • Contactați DPO prin poștă

Le délégué à la protection des données
Oneytrust
34 avenue de Flandre
59170 Croix
FRANCE

Reclamație

Puteți adresa orice reclamație referitoare la prelucrarea cererilor dumneavoastră de către Oneytrust, scriindu-i Responsabilului cu protecția datelor. Acesta va face tot posibilul pentru a răspunde la orice reclamație și pentru a încerca să rezolve neînțelegerea.
Dacă, după ce ne-ați contactat, considerați că drepturile dumneavoastră nu sunt respectate, puteți face o reclamație (plângere) la autoritatea locală de protecție a datelor personale de care aparțineți sau la autoritatea de protecție a datelor personale de care aparține Oneytrust, și anume CNIL – 3 place de Fontenoy – TSA 80715 – 75334 Paris cedex 07 (FRANCE).