Data protection policy

Created 28 February 2024
Updated 22 September 2026

About this article

Created 28 February 2024
Updated 22 September 2026

As data controller, the company Biocodex, established in France at 22 rue des Aqueducs in Gentilly (94250) (hereinafter, the “Controller”), undertakes to comply with the regulatory provisions applicable to the protection of personal data, in particular Regulation (EU) 2016/679 of April 27, 2016 – General Data Protection Regulation (hereinafter, the “GDPR”), and the French Law of 20 June 2018 on the protection of personal data (the amended French “Data Protection Act”) on the processing that it implements on the Biocodex Microbiota Institute’s website, accessible at www.biocodexmicrobiotainstitute.com (hereinafter, the “Website”).


Definitions

For the purposes of this Policy, the terms used shall have the meanings given to them in Article 4 of the GDPR.

The terms “data” and “processing” used below, whether in the singular or plural, refer to the personal data and processing of personal data described in this Policy.

Generalities

The User is free to browse the Website without having to explicitly provide any personal information. However, he/she may be asked to provide personal data, for example by contacting the Controller. In addition, the Website uses "cookies", which may send data concerning the User to third-party companies.

The Website, as well as each service offered on the Website, limits the collection of personal data to what is strictly necessary and is accompanied by information detailing in particular:

  • The purpose of the processing of personal data,
  • The legal basis for the processing,
  • The source of the data (if not supplied by the Website user),
  • Whether data collection is mandatory or optional,
  • Recipients of the data,
  • Data retention period,
  • Whether data is transferred outside the European Union,
  • The rights of the individual to his or her data and how to exercise them.

 

Security measures

BIOCODEX takes all appropriate precautions to preserve the security and confidentiality of the User’s personal data by implementing appropriate technical and organisational measures designed to prevent such data from being accidentally or unlawfully destroyed, lost or altered, or accessed by unauthorised third parties.

GDPR rights

The User has the right to access, correct, delete, and transfer their data; they may object to the processing of their data or request that such processing be restricted; they may establish guidelines regarding the handling of their data after their death.

These rights must be exercised in accordance with the conditions set forth in the GDPR and the amended “Data Protection Act.”

To exercise these rights or for any questions regarding the processing of their data, Users may contact BIOCODEX’s Data Protection Officer (DPO):

- By email: dpo[at]biocodex.com (replace “[at]” with “@”)

- By mail: BIOCODEX DPO, 22 rue des Aqueducs, 94250 GENTILLY (France)

These rights may be exercised only with respect to data concerning the User, either by the User themselves or by a person authorized by them. The User may be asked to provide proof of identity if the information provided in their request does not allow for their unambiguous identification.

In the event of a complaint, the User may file a complaint with a supervisory authority, such as the CNIL in France (see https://edpb.europa.eu/about-edpb/about-edpb/members_fr).

Website management

What is the purpose of the processing and what is its legal basis?

The purpose of processing personal data is to manage the Website. It enables the Controller:

  • The preparation and publication of content;
  • Putting services on line for users;
  • Technical administration, in conjunction with the service providers involved in processing;
  • Security management;
  • Production of statistics on audience and use of online services.

With reference to Article 6(1)(f) of the GDPR, the processing is necessary for the purposes of the legitimate interests pursued by the Controller (promote research on microbiota and their interaction with various pathologies).

What data is processed, where they come from and how long are they kept?

The categories of data processed are:

  • Data relating to the persons who are the subject of publications (identity, functions, contact details, etc.);
  • Data relating to browsing on the Website (time stamps, users' IP addresses, technical data relating to the equipment and browser used by users, geolocation, cookies) and on digital platforms via share buttons and media (cookies and other tracers);
  • Data relating to the management of services offered to users;
  • Data relating to the management of publications (purpose, deliverables, follow-up, statistics);
  • Data relating to the management of technical services (time-stamping and purpose of requests, tracking, follow-up, statistics);
  • Website audience and online services usage statistics.

Data may come from:

  • The Controller staff in charge of publishing content and technical administration of the Website;
  • Contributors to publications;
  • Website users;
  • Staff of the service providers concerned;
  • Third-party sites (websites, social networks, search engines, etc.).

Data collected during browsing, which is not necessary for the operation of the Website (such as some types of cookies), is optional. Unless otherwise specified, all other data collected is mandatory.

Data retention:

  • Published data is kept online until the site is closed, after which it is archived for 5 years;
  • Data relating to exchanges with service providers are kept for 5 years after the end of the contractual relationship;
  • Unless required by law, or unless there is a particularly high risk, Log data are retained for a maximum of 1 year;
  • The data required to produce statistics on audience and online service usage is retained for 25 months in a format that does not allow individuals to be identified by their IP address, and includes an identifier (related to the cookie) that is retained for a maximum of 13 months, unless the data subject objects.

Who is the data intended for?

Depending on their respective needs, the following are recipients of all or part of the data:

  • The Controller staff in charge of content publication and technical administration of the Website;
  • Staff of the service providers concerned;
  • Website users;
  • Staff responsible for supervising the security of the Controller’s information systems.

Due to their presence on the Internet, publications may be accessible outside the European Union.

Other data are not transferred outside the European Union. However, where tools or service providers located outside the EU are used, BIOCODEX will ensure that appropriate safeguards (standard contractual clauses, adequacy decisions, etc.) are in place.

Management of requests

What is the purpose of the processing and what is its legal basis?

The purpose of processing personal data is to manage requests and reports made on the Website. It enables the Controller:

  • Receive requests/notifications;
  • Manage the follow-up of correspondence;
  • Drawing up anonymous activity statistics.

With reference to Article 6(1)(f) of the GDPR, the processing is necessary for the purposes of the legitimate interests pursued by the Controller (collecting requests and reports from users from its websites).

What data is processed and how long are they kept?

The categories of data processed concerning the sender are:

  • Identity: e-mail address;
  • Subject and body of the message.

Unless otherwise specified, all data is mandatory.

Data is kept for up to 5 years from the time the request is processed. If the request concerns an adverse reaction, a medical question or a product quality complaint, data retention is defined in the specific subsequent processing.

Who is the data intended for?

Depending on their respective needs, the following are recipients of all or part of the data:

  • The data subject;
  • Controller staff responsible for:
    • processing requests;
    • health vigilance, medical information or product quality complaints (where applicable);
    • data protection (where applicable).
  • The staff of the relevant service providers;

Subscription to the newsletter

What is the purpose of the processing and what is its legal basis?

The Controller allows the User to subscribe to the Website’s newsletter, in order to be kept informed of the news associated with the Website and to download documents. This processing of personal data allows the Controller to:

  • Manage subscriptions and electronic mailings;
  • Develop service statistics.

With reference to Article 6(1)(a) of the GDPR, the data subject has given consent to the processing of his / her personal data.

By subscribing to the newsletter, the User agrees to the confidential and secure processing of her/his data in the unified marketing campaign management solution implemented by the Controller and, as a result, he agrees to be profiled. As such, he may or may not accept to receive other communications and commercial offers from the Controller.

The User may unsubscribe (withdraw consent) via the unsubscribe link in the communications received.

What data is processed and how long are they kept?

The categories of data processed concerning the sender are:

  • Identity: e-mail address;
  • Technical data required to record and retain the history of consent;
  • Subscription date;
  • Statistics relating to the service.

The collection of the e-mail address is mandatory for the sending of communications from the Controller.

The Controller retains the e-mail address as long as the person concerned does not unsubscribe (via the unsubscribe link included in the newsletters).

Who is the data intended for?

Depending on their respective needs, the following are recipients of all or part of the data:

  • The User of the Website subscribed to the newsletter;
  • The Controller’s staff in charge of managing the newsletter service, publishing content, technical administration of the Website;
  • The personnel of the service providers concerned by the Website.

As the newsletter service may be provided by a third party, the data may be transmitted outside the European Union.

Where tools or service providers located outside the EU are used, BIOCODEX will ensure that appropriate safeguards (standard contractual clauses, adequacy decisions, etc.) are in place.

About cookies

The Controller uses various computer "cookies" on the Website to measure the audience and integrate services to improve the interactivity of the Website.

What is a computer "cookie"?

A computer "cookie" is a text file that may be deposited on a user's terminal during browsing on a website. Cookies are an important tool enabling organizations to gain an overview of their users' online activity.

How it works: generally small in size and identified by a name, it is transmitted to the user's browser by the website visited. The browser stores it for a certain period of time, and sends it back to the website each time it is reconnected. In principle, cookies can be easily viewed and deleted.

In themselves, cookies are harmless, as they contain no executable code. They perform important functions for websites: they can be used to memorize a customer account identifier, browsing preferences, enable browsing to be tracked for statistical or advertising purposes, and so on.

However, cookies can store enough data to identify a user without his or her consent and, in some cases, can be used to create profiles of individuals. This is why it is essential that cookie management is controlled within the framework of data protection.

What are the different types of cookies?

In general, cookies can be classified in three different ways: by origin, by lifetime and by purpose.

Origin

First-party cookies - These cookies are placed on the visitor's terminal directly by the website being visited.

Third-party cookies - These cookies are placed on the visitor's terminal by a third-party organization, such as an advertiser.

Lifetime

Session cookies - These cookies are temporary and expire when the browser is closed or at the end of the visit (session).

Persistent cookies - This category includes all cookies that remain on the visitor's terminal until they are deleted. They may be deleted manually or automatically (depending on the expiration date of the cookie, or when the browser is closed if so configured).

Purpose

Strictly necessary cookies - These cookies help to make a website usable by enabling basic functions such as page navigation, access to secure areas of the site, or storing items in an online shopping cart. The website cannot function properly without these cookies.

Preference cookies (functionality cookies) - These cookies enable a website to retain information that modifies the way the site behaves or displays, such as the visitor's preferred language or the region in which he or she is located.

Statistical cookies (performance cookies) - These cookies help the website owner, through the collection and communication of information, to understand how visitors interact with the site, such as which pages are visited and which links are used. The aim is to subsequently improve the website. Although intended for use by the website owner, these cookies may come from third-party organizations that may track the visitor for marketing purposes.

Marketing cookies - These cookies track the user's online activity to help, for example, advertisers deliver more relevant ads. These cookies may share this information with other organizations or advertisers. These cookies are persistent and almost always come from third parties.

How can I control the placement of cookies?

In general, website users can prevent cookies from being deposited on their terminal, or delete existing ones, by configuring their web browser accordingly. For instructions on how to manage cookies, please refer to your browser's help section.

  • Please note, however, that blocking the deposit of cookies in your web browser may lead to malfunctions on the Website, as well as on other websites.

What types of cookies are used on the Website?

Internal cookies storing the result of user consent

These cookies are deposited directly by the Website and enable the User's choices on the deposit of third-party cookies to be retained.

 

"Didomi token (didomi_token)":

- Purpose: contains consent information for personalized purposes and for personalized partners, as well as information specific to Didomi (user ID, for example) ;

- Maximum retention period: 6 months.

Third-party cookies 

The Website relies on certain services offered by third parties. These may include, for example, audience measurement services, video hosting services, etc.

The purposes served by these third parties use cookies deposited directly by these services. Via these cookies, these third parties may collect and use the user's browsing data on their own behalf in order to offer, for example, targeted advertising and content based on the user's browsing history. For further information, the User can consult the privacy policy of these third parties via the cookie management module set up on the Website.

By default, these third-party cookies are not stored. The User is informed of the third-party cookies used and can consent to their deposit in the cookie management module or directly via a contextual consent request, for example by activating the playback of an external video. He/she can indicate its preferences, either globally for the Website, or service by service. He/she can reverse its choices at any time by calling up the cookie management module via a permanent link at the bottom of the page.

Data collected by third-party cookies may be transferred outside the European Union.

Specific case of third-party cookies placed by “gatekeepers” (*):

BIOCODEX has opted for maximum compliance with the GDPR and the DMA (European Digital Markets Act) by adopting a consent management system and procedures designed to ensure that only strictly necessary data are transmitted to third-party companies.

By refusing cookies from “gatekeepers”, the User of the Website is assured that only anonymous data are sent to these third parties.

(*) These are major digital companies operating on the Internet: Alphabet (Google), Amazon, Apple, Meta (Facebook), Microsoft and ByteDance (TikTok).

Measurement of the use of our electronic communications

Where you have agreed to receive our electronic communications, these may, subject to your preferences, contain tracking pixels.

What is a tracking pixel?

A tracking pixel is a very small image embedded in an email that can collect certain information when the email is viewed. Like cookies, it is a tracking technology whose use is subject to your prior consent, unless an exemption is provided for by applicable regulations.

Why do we use tracking pixels?

We use tracking pixels to measure the performance of our communications, improve their content and relevance and, where applicable, personalise them based on your interactions.

Certain information relating to the opening of our emails may also be used for deliverability purposes, in particular to identify inactive recipients.

What is the legal basis for using these technologies?

Where tracking pixels are used to measure the performance of our campaigns or to improve or personalise our communications, their use is based on your consent.

Important: Your consent to the use of tracking pixels is separate from your choice to receive our electronic communications. You may therefore continue to receive communications to which you have subscribed while refusing the use of tracking pixels subject to your consent.

In the cases strictly provided for by applicable regulations, certain pixels necessary to provide a service you have requested, in particular where they are used exclusively for deliverability purposes, may be used without your consent.

What data may we collect?

Tracking pixels may collect information relating to the viewing and use of our emails, including whether they have been opened, clicks made, an identifier associated with the recipient and certain technical data relating to the device used. This information is associated with your email address.

Who may have access to this data?

Within the limits of their respective responsibilities, this data may be accessed by:

- authorised BIOCODEX personnel, in particular teams responsible for communications, marketing and customer relationship management;

- technical service providers involved in the management and sending of our electronic communications.

How long do we retain this data?

Information obtained through tracking pixels is retained for a maximum period of 6 months from the date of collection and is then deleted or anonymised.

Where pixels are used exclusively for deliverability purposes, only the date of the most recent opening, recorded by day, is retained. This information is updated each time a new opening occurs and is retained for the period necessary to manage the deliverability of our communications.

Can your data be transferred outside the European Economic Area?

Certain data may be transferred or made accessible outside the European Economic Area (EEA) by our service providers. Where the country concerned is not covered by an adequacy decision issued by the European Commission, such transfers are subject to appropriate safeguards in accordance with applicable regulations.

How can you manage your preferences?

You can change your choices regarding tracking pixels at any time by using the link provided in our communications or via our preference centre.

Withdrawing your consent to tracking does not unsubscribe you from our communications. If you wish to unsubscribe, please use the specific unsubscribe link provided in our communications or our preference centre.