PRIVACY NOTICE

Privacy Notice

Version 1.1 — 19 August 2026

PKDERM SAS (“PKDERM”, “we”, “us”) is committed to protecting the personal data of everyone we deal with — clients, prospects, partners, job applicants and visitors to our website. This notice explains what personal data we process, why, on what legal basis, how long we keep it, and the rights available to you.

It is written under the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the French Data Protection Act (Loi n°78-17 Informatique et Libertés).

1. Who we are

PKDERM SAS is a French contract research organisation providing animal-free in vitro and ex vivo testing services to the cosmetics, dermatology, pharmaceutical, chemical, agrochemical and medical device industries.

Registered office: 28 Corniche Valmare, 06600 Antibes, France.

Laboratories: 80 Route des Lucioles, Espaces de Sophia, Bâtiment N, 06560 Valbonne, France.

For the processing described in this notice, PKDERM acts as the data controller.

Data protection contact: Dr Hanan Osman-Ponchet, Founder, CEO & CSO — contact@pkderm.com.

Security incidents: security@pkderm.com, or ssi@pkderm.com for encrypted and PGP-signed correspondence.

2. Scope of this notice

This notice covers personal data that PKDERM processes as a controller: visitors to pkderm.com, business contacts and prospects, contacts met at trade shows and partnering events, job applicants, and the representatives of our clients, suppliers and partners.

It does not cover personal data that PKDERM processes on behalf of a client in the course of study services. In that situation the client is the controller and PKDERM acts as a processor, under the Personal Data Protection Policy that forms part of our client agreement. That document sets out our obligations on instructions, confidentiality, security, sub-processing, breach notification, cross-border transfers, audit and deletion. It is available to clients and prospective clients on request.

Human biological samples used in our studies (skin explants, lung tissue) are supplied to us in coded or pseudonymised form by tissue suppliers and hospital partners operating under their own donor consent and ethics frameworks. PKDERM does not receive, and does not seek, data identifying individual donors.

3. What we process, why, and on what legal basis

ActivityDataPurposeLegal basisRetention
Website contact formName, email address, subject, messageAnswering your enquiryOur legitimate interest in responding to a request you addressed to us (Art. 6(1)(f)); where the enquiry concerns our services, steps taken at your request prior to entering into a contract (Art. 6(1)(b))3 years from our last contact with you
Business correspondence, quotations and CRMName, business email and telephone, employer, role, record of exchangesManaging the commercial relationship, issuing quotations and proposals, following upPerformance of a contract, or our legitimate interest in developing our business (Art. 6(1)(b) and (f))Prospects: 3 years from last contact. Clients: duration of the contract plus 5 years
Trade shows and partnering events (BioJapan, in-cosmetics, Cosmetotest and similar)Business card details, profile data from event partnering platforms, meeting notesFollowing up on meetings and pursuing business opportunitiesOur legitimate interest in business development (Art. 6(1)(f))3 years from last contact
Job applicationsContact details, CV, cover letter, career and education historyAssessing your applicationSteps taken at your request prior to a possible employment contract (Art. 6(1)(b)); consent for retention in our talent pool2 years from our last contact, in line with CNIL guidance, unless you ask us to delete it sooner
Supplier and partner contactsName, business contact details, roleManaging the relationshipPerformance of a contract or our legitimate interest (Art. 6(1)(b) and (f))Duration of the relationship plus 5 years
Website technical logsIP address, browser and device information, timestamps, pages requestedSecurity, availability, detection and prevention of abuseOur legitimate interest in keeping our site secure (Art. 6(1)(f))12 months maximum
Audience measurement and embedded third-party contentSee section 4Understanding how the site is used; displaying a map and video contentConsent where required by Art. 82 of the French Data Protection Act; strictly necessary cookies are exempt13 months maximum

We do not sell personal data, and we do not use it for automated decision-making producing legal or similarly significant effects.

4. Cookies, audience measurement and third-party content

Our website runs on WordPress and sets a small number of strictly necessary cookies required for the site to function. These do not require your consent.

Audience measurement is carried out with Koko Analytics, a self-hosted plugin. The statistics are stored in our own WordPress database, nothing is sent to a third-party service, no personal data is recorded, and no cookie is used. On that configuration the measurement falls within the exemption from consent recognised by the CNIL for audience-measurement tools.

Our pages currently load web fonts from Google Fonts servers (fonts.googleapis.com and fonts.gstatic.com). When a page is displayed, your IP address is therefore transmitted to Google, which acts as an independent controller for that data under its own privacy policy. We are migrating these fonts to our own server so that this transfer no longer takes place. In the meantime, if you would prefer to avoid it, a browser extension blocking third-party font loading will prevent the request.

Our site links to our YouTube channel and our LinkedIn page. Following one of those links takes you to the provider's own site, governed by its own privacy policy. Our Contact page shows a static map image hosted on our own server: displaying it calls no third party, and only clicking it opens an external map service.

We do not use advertising, retargeting or profiling cookies, and we do not sell or share data with advertisers.

You can configure your browser to refuse or delete cookies at any time. If you would like us to tell you exactly what is set on your visit, write to contact@pkderm.com.

5. Who has access to your data

Your data is accessible to the PKDERM staff who need it for the purposes described above. All staff are bound by a confidentiality clause in their employment contract and must accept our IT Charter before being granted access to our information system.

We also use a limited number of service providers acting as processors on our instructions: our website host, our email and office productivity provider, IT support and backup providers, and, where relevant, professional advisers. Each is bound by a written contract meeting the requirements of Article 28 GDPR.

We may disclose data where we are legally required to do so, or to establish, exercise or defend legal claims.

6. International transfers

PKDERM is established in France and processes personal data primarily within the European Economic Area.

Where personal data is transferred outside the EEA, we rely on one of the safeguards permitted by Chapter V GDPR: an adequacy decision of the European Commission, or the European Commission's Standard Contractual Clauses together with any additional measures required by the circumstances of the transfer.

In particular, business contact data exchanged with counterparts in Japan is covered by the European Commission's adequacy decision of 23 January 2019 concerning Japan, which recognises that Japan ensures an adequate level of protection for personal data transferred from the EU.

You may request a copy of the relevant safeguards by writing to contact@pkderm.com.

7. How we protect your data

PKDERM applies technical and organisational measures appropriate to the nature of the data and the risks presented by the processing. These include, in particular:

  • Hosting with a provider certified to ISO/IEC 27001, 27017, 27018, 27701, 22301 and ISO 9001, and to CSA STAR CCM v4.0
  • Badge-controlled access to our premises, and a dedicated guest network for visitors
  • Named individual accounts, a proxy restricting internet access, a firewall and an intrusion prevention system
  • Remote access exclusively through a secure SSL VPN
  • Backup and recovery through network-attached storage, mirrored backup systems and secure cloud storage, with access restricted to authorised personnel
  • Logging of access to administrative systems
  • Confidentiality clauses in employment contracts, an IT Charter that every user must accept, and staff awareness measures
  • A documented incident reporting procedure with a dedicated security contact and an encrypted reporting channel

8. Your rights

Under the GDPR and the French Data Protection Act you have the right to request access to your personal data; to have inaccurate data corrected; to have your data erased; to have processing restricted; to object to processing carried out on the basis of our legitimate interest, including any processing for direct marketing purposes; to receive data you provided to us in a portable format; to withdraw your consent at any time where processing is based on consent; and to give directives on what happens to your data after your death.

To exercise these rights, write to contact@pkderm.com or to PKDERM SAS, 28 Corniche Valmare, 06600 Antibes, France. We may need to verify your identity. We will respond within one month, which may be extended by two further months where the request is complex, in which case we will tell you.

If you consider that your rights have not been respected, you may lodge a complaint with the French supervisory authority: Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr.

9. Changes to this notice

We review this notice periodically and will publish any updated version on this page with a new version number and date. Where a change materially affects how we use your data, we will take reasonable steps to inform you.