Other Covered Entities

EcoVadis Inc.

Industries

  • Business and Professional Services
  • Management Consulting Services

Participation

EU-U.S. Privacy Shield Framework: Active

Original Certification Date: 1/19/2017
Next Certification Due Date: 1/25/2019
Data Collected: HR, NON-HR

Purpose of Data Collection

EcoVadis operates a Sustainability and Cyber security Monitoring platform dedicated to facilitating the management of suppliers environmental and social performance as well as cyber security performance offered as a Software- as-a-Service (SAAS) model. Our Privacy Shield commitment covers human resources information we collect in the context of the employment relationship as well as other personal information that we collect from actual and potential customers. In order to deliver the services we collect personal information from users of our web Services including but not limited to sites located at www.ecovadis.com, www.ecovadis-survey.com, www.cybervadis.com, all subdomains, and all other online services of EcoVadis SAS or EcoVadis Inc. (Services) Information provided to EcoVadis by our corporate customers is collected by those customers under their own privacy policies. The personal information that we collect from our customers and potential customers and the human resources data that we collect from our employees are stored in a data center in the EU. The databases are accessible by certain employees that are located in the United States. We limit access to this information to only those employees who are necessary to carry out the below listed purposes. We use the personal information we collect from our customers and potential customers for the following purposes : (1) contract and billing administration, (2) product and service delivery, (3) call and chat recordings from support services (4) communications regarding marketing and technical information concerning our products and services, (5) customer account management, (6) website audience tracking and viewer statistics for customer prospection, and (7) fulfillment of our business obligations to our customers. We use human resources data we collect from our current and potential employees only for the following purposes: (1) the management and operations of our company, its functions and activities, (2) employee communications, including employee surveys, (3) global directory maintenance, (4) execution of obligations under employment contracts and employment, tax and benefits laws, and in connection with other working relationships or arrangements, (5) development and training programs, (6) recruitment and hiring of job applicants, (7) background checks and verification of references, (8) assessment of qualifications and employee performance, (9) evaluation of employee compensation or payment, (10) management of physical and logical access to the offices and the EcoVadis network, (11) organization of professional elections (personnel representatives), (12) inventory of IT assets and implementation of devices to ensure the security and operation of computer applications and networks (13) other general human resources purposes. EcoVadis does not sell, rent or lease personal information to third parties. EcoVadis may share usage data with trusted partners to help perform statistical analysis of usage or to provide customer support. All such third parties are prohibited from using a user?s Personal Information except to provide these services to EcoVadis, and they are required to maintain the strict confidentiality of user information.

Privacy Policy

HR Data

Confidentiality and data protection policy
Description:

The purpose of this policy is to enable EcoVadis to: ● Comply with the law in respect of the data it holds about individuals; EcoVadis complies with The European Data Protection Directive (Directive 95/46/EC), and its transposition into national French law ( CNIL ) and is registered under the number 1302092 since July 2008. EcoVadis is also compliant with the DPA (Data Privacy Act) UK regulation and adheres to the United States Department of Commerce’s Privacy Shield framework. ● follow good practices; ● protect EcoVadis’ Clients, Assessed Suppliers, Staff and other Individuals ● protect EcoVadis’ Clients and Assessed Suppliers from the business consequences of a breach of confidentiality on the confidential information shared with EcoVadis ● protect EcoVadis from the consequences of a breach of its responsibilities. ● Protect EcoVadis Intellectual Property and from any form of industrial espionage threats

Effective Date: 6/7/2016

Non-HR Data

Description:

Practices regarding “Personal Information” (as defined below) which we collect from users of our web Services including but not limited to sites located at www.ecovadis.com, www.ecovadis-survey.com, all subdomains, and all other online services of EcoVadis SAS or EcoVadis Inc. (“Services”)

Effective Date: 1/4/2017

Verification Method

Self-Assessment

Dispute Resolution

Questions or Complaints?

If you have a question or complaint regarding the covered data, please contact EcoVadis Inc. at:

Frank Pithan
Data Protection Officer
EcoVadis Inc.
EcoVadis SAS, Paris
205E 42nd St, 20th floor
New York, New York 10017

Privacy Shield organizations must respond within 45 days of receiving a complaint.

If you have not received a timely or satisfactory response from EcoVadis Inc. to your question or complaint, please contact the independent recourse mechanism listed below


NON-HR RECOURSE MECHANISM



Appropriate statutory body with jurisdiction to investigate any claims against EcoVadis Inc. regarding possible unfair or deceptive practices and violations of laws or regulations covering privacy Federal Trade Commission