AdaCore: Build Software that Matters
AdaCore Hero Image

Privacy Policy

At AdaCore, your privacy is important to us. This policy specifies the rules and principles AdaCore applies in the Processing of Personal Data of the users of AdaCore’s website, sales prospects, and customers (“You”), and as such informs You:

  • On how Your Personal Data is collected.
  • On the rights you have in relation to Your Personal Data.
  • On the Recipients of Your Personal Data.
  • On how long Your Personal Data is kept at AdaCore.
  • On the security measures with which Your Personal Data is kept at AdaCore.

Definitions

“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council on the Protection of Natural Persons with regard to the processing of personal data and on the free movement of such data.

“UK GDPR” has the meaning given to it in the GDPR as made part of United Kingdom law by virtue of section 3 of the United Kingdom’s European Union (Withdrawal) Act 2018.

“Data Protection Laws” means all applicable data protection and privacy laws, as may be amended or superseded from time to time, including, but not limited to: (a) the GDPR; (b) the UK GDPR; (c) all applicable national data protection laws made under, pursuant to, or that apply in conjunction with any of the above; and (d) any other applicable national or state-level data protection laws.

“Personal Data” means any information relating to an identified or identifiable physical person (“Data Subject”). It may include, but is not limited to their first and last names,  email address, location, or IP address.  It does not include data relating to a business or similar entity.

“Controller”, “Joint Controllers”, “Data Protection Officer”,  “Recipients”, and “Sub-Processors” shall have the same meaning as given to them by the GDPR and the UK GDPR.

“Processing": shall have the same meaning as given by the GDPR and the UK GDPR: “any operation or set of operations applied to personal data, regardless of the process used (e.g. but not limited to collection, recording, organization, storage, adaptation or modification, extraction, consultation, use, communication by transmission, erasure or destruction).”

What Personal Data are we collecting?

When you submit a  form, we collect the data you entered in that form.

We also use cookies and other traffic analysis tools to better understand our audience and improve website navigation. You may find our cookie policy at this link.

We may also collect data during phone calls and in person.

Collectively, all such Personal Data is referred to as “Your Personal Data”.

Why are we collecting your Personal Data?

Your Personal Data is collected for a specific, explicit, and legitimate purpose specified at the time and place the data is collected. We will use it only for that purpose.

Why is it legal?

The legal basis for Processing Your Personal Data depends on the context. We may do that:

  • With your consent, for example, when you request pricing information on our website.
  • As a preliminary step toward entering into a contract with you, such as when you submit an employment application or request a quote from us.
  • To perform a contract to which you are already a party, such as when we provide a subscription service to you and open your access to GNAT Tracker.
  • To protect our legitimate interests, such as when we log IP addresses connecting to our website or the addresses of received and sent emails.

Who has access to Your Personal Data?

As part of the AdaCore group's usual activities, authorized third parties may be Recipients of or have access to Your Personal Data.  For instance, Your Personal Data is accessible to employees and consultants of all entities that comprise the AdaCore group. If you make a request relating to solutions we provide jointly with another company, we may also share with them the data needed to answer that request. In addition, we may disclose Your Personal Data to our IT providers, to be used by them exclusively on our behalf and under our control. Other than those cases, we never disclose Your Personal Data to third parties.

AdaCore ensures transfers of Your Personal Data are necessary and within the stated purpose(s) of the Processing(s) and also provides appropriate data protection guarantees.

AdaCore maintains a list of Sub-Processors accessible on its website.

Where will Your Personal Data go?

As the AdaCore group is an integrated multinational organization, Your Personal Data will be transferred, in accordance with the purposes of the processing, between the European Economic Area (EEA) the UK and the United States, with appropriate safeguards ensuring the protection and security of Personal Data.

How long will Your Personal Data be stored?

The retention period of Your Personal Data varies and depends on the purposes pursued, AdaCore's legitimate interests, the legal and regulatory obligations applicable to AdaCore, or the nature of the concerned Personal Data.

Your Personal Data will be kept for:

  1. a reasonable period of time after the termination of the contract between us, whenever the Processing is based on a contract; or
  2. a reasonable period of time after the end of the pre-contract discussions between us, when the Processing is based on such discussions; or
  3. as long as we have your consent, whenever the Processing is based on your consent; or
  4. as long as we have a legitimate interest, whenever the Processing is based on our legitimate interest.

However, Your Personal  Data may remain in disaster-recovery systems or with third-party providers for a longer period.

How do we ensure the security of Your Personal Data?

Security is essential to AdaCore’s activities.

AdaCore takes all appropriate security measures to ensure the security and confidentiality of Your Personal Data with a view to protecting it against any loss, accidental destruction, alteration, and unauthorized access. In particular, AdaCore is compliant with CMMC level 2.

We choose only Subcontractors, service providers, or partners that have adequate security and confidentiality processes in place.

In the event of a breach of Your Personal Data, AdaCore will notify You and/or the competent supervisory authority as required by the applicable Data Protection Laws as soon as possible after the breach, so that you can take necessary measures.

If you want to know more about our security measures, please refer to our security policy.

What are your rights?

When the Processing of Your Personal Data is based on your consent, you can withdraw your consent at any time. When practical, we provide online means to do so.

At any time, provided that certain legal conditions are met, you can make a formal request to:

  • Your right of access to Your Personal Data.
  • Your right to rectification of Your Personal Data.
  • Your right to erasure of Your Personal Data.
  • Your right to restrict the Processing of  Your Personal Data.
  • Your right to object to the Processing of Your Personal Data.
  • Your right to portability of Your Personal Data.
  • Your right to withdraw your consent.
  • Your right to lodge a complaint.
  • Your right to define post-mortem guidelines on the Processing of Your Personal Data.

Such requests must be made to AdaCore’s Data Protection Officer (“DPO”) at dpo@adacore.com and include both your name and the purpose of the Processing in question. The DPO will respond to your request within one (1) month.

More generally, you can direct any privacy-related questions to AdaCore at the address above.

If You believe your rights were infringed, You can lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL) at the following postal address: 3 Place de Fontenoy 75007 PARIS or at the following link: https://www.cnil.fr/fr/saisir-la-cnil/nous-contacter

Who is responsible for this Processing?

AdaCore and its entities of the AdaCore Group are Joint Controllers of this Processing: they are the legal entities responsible for the Processing of Personal Data. You can contact us at:

AdaCore 
46 rue d’Amsterdam
75009 PARIS
RCS PARIS : 403 325 657
privacy[at]adacore.com

What are the obligations and roles of each of these joint controllers?

AdaCore and its affiliates unanimously agree on:

  • the internal procedures to ensure compliance with Data Protection Laws; and
  • the Processings to be performed, their purposes, and the means assigned to each of them; and
  • the individuals assigned to answer privacy-related requests.
  • Each company is responsible for dedicating the necessary resources to these tasks.

Who is the Data Protection Officer (“DPO”)?

AdaCore’s DPO is Lawways Avocats (RCS PARIS 489 534 479).

You can contact our DPO at:

Lawways Avocats
5 rue de la Boétie
75008 PARIS
dpo[at]adacore.com

When will this Privacy Policy change?

We may make changes to this policy from time to time due to new legal requirements or for other business purposes. However, no such change will affect your rights under the law.