Video Calls Recording Privacy Notice

Criteo takes your privacy very seriously. This Privacy Notice describes how Criteo as data controller (“we”, “us”, “our”) collects, uses and secures your personal data as part of any Video conference recording process, and also describes your rights regarding our use and your access to your personal data.

How your personal data will be used

Criteo has a legitimate interest in recording video calls of our Sales teams in the workplace with their external clients or prospects. Processing data from Video Calls allows us:

· to train our Sales teams (for instance by reusing recordings to illustrate a point during training sessions);

· improve Sales team and Account Strategist performance, and

· improve service quality (for instance by allowing sales teams to examine the type of response given to the client).

Conference call recordings are performed on an ad hoc basis in accordance with objective criteria which are determined by Criteo and disclosed to the employees concerned.

What personal data will be collected

The data we hold and process includes:

– Identification data: first name and last name

– Professional data: position, professional email address, professional phone number

– Connection data (IP address, logs)

– The Video Call recording,

– The Video Call audio file,

– The Video Call transcript.

· Support the recording of the Video Call

The processing of your personal data implies the transfer of your personal data outside of the European Union. In accordance with European data protection regulation, this transfer is covered by Standard Contractual Clauses as approved by the European Commission. You can access such safeguards by sending a request to dpo@criteo.com.

When Do We Disclose Your Personal data?

The recording is directly available for the video call host, i.e the Criteo employee who proceeds with the recording. On a need-to-know basis, the data is shared with:

– The employee manager and training teams for the purpose of training and improving performance and service quality;

– The above mentioned Criteo data processors for hosting purposes mainly;

– The IT/Admin support teams if access to the data is necessary for the performance of their roles or any admin-related task.

Confidentiality, Security and Retention

We take the confidentiality and the security of your data seriously.

We have internal policies and controls in place to ensure that your data is not lost, accidentally destroyed, misused or disclosed, and is not accessed except by our authorized employees in the proper performance of their duties.

Personal data is retained for a maximum of six (6) months from the date of collection. After this period, the data will be deleted.

Your rights

Under the General Data Protection Regulation (GDPR) you have the following rights with regard to your personal data:

– Right to access: you have the right to access, at any time, to your personal data.

– Right to erasure: In certain circumstances, you have the right to obtain from Criteo the erasure of your personal data;

– Right to request rectification : You have the right, at any time, to request rectification of your personal data, which would not be accurate or complete;

– Right to restrict: You have the right to restrict the processing of your personal data in certain circumstances, and can request Criteo to limit the way we use your data;

– Right to object: You have the right to request that your personal data be not collected and/or be not used, provided that it does not impact on the good running of the company;

Should you have any request relating to your personal data, please send your request to our Data Protection Officer by email or mail at the contact details indicated below.

You may lodge a complaint with a supervisory authority, for instance in France: CNIL (www.cnil.fr) if you believe that we have not complied with the requirements of the GDPR with regard to your personal data.

Identity and contact details of controller and Data Protection Officer

Criteo is the data controller and our Data Protection Officer can be contacted by email or mail:

• By email dpo@criteo.com

• By mail DPO-CRITEO – 32 Rue Blanche -75009 Paris – France