Skip to content

Secure data

Privacy policy: how France Surgery protects your personal data and health data on the iris-prevention.fr website and the Iris platform. Version dated 17 September 2026.

What is this policy for?

France Surgery, publisher of the iris-prevention.fr website and the Iris health prevention platform, attaches great importance to the protection and confidentiality of your personal data, which we regard as a mark of professionalism and trust.

This policy reflects our commitment to complying, within France Surgery, with the rules applicable to personal data protection and, in particular, the General Data Protection Regulation (“GDPR”) and the French Data Protection Act.

Its purpose is to inform you, clearly and transparently, about the data we process, why we process it, how long we keep it, who has access to it and the rights you have.

Who does it apply to?

This policy applies to you, wherever you live, if:

• you browse the iris-prevention.fr website (visitor);

• you contact us or request a demo (prospect, representative of a client company);

• you use the Iris platform as part of a prevention campaign offered by your employer or organisation (beneficiary).

The Iris platform is reserved for adults. If you believe we hold data about a minor, please contact us at dpo@iris-prevention.fr so that we can delete it.

Who is responsible for your data?

The controller for the processing described in this policy is:

FRANCE SURGERY, SAS with share capital of €43,780, RCS Toulouse 515 151 835, 11 rue Saint-Expédit, 31500 Toulouse, France — contact@iris-prevention.fr.

France Surgery is the data controller for the whole prevention pathway it organises: it designs the questionnaires, calculates the scores, refers you to partner healthcare professionals and produces the indicators. Under some contracts, however, the client company may designate France Surgery as a processor; in that case the client company is the controller and provides you with its own privacy notice, this policy remaining applicable to anything it does not cover.

The partner healthcare professionals you consult after your check-up are controllers for the medical record they create, in accordance with their own obligations.

What data do we process, why, and on what legal basis?

On the iris-prevention.fr website:

• Contact and demo request forms — e-mail address (main data), and optionally name, company, job title, phone number and message — to answer your request and get back to you, based on our legitimate interest in responding to enquiries and developing our business.

• Newsletter and communications — e-mail address — based on your consent (you can unsubscribe at any time).

• Audience measurement — pages viewed, device type, browser, country, referral source, with no cookie and no persistent identifier — to improve the website, based on our legitimate interest.

• Security and logging — IP address, technical logs — to keep the website secure, based on our legitimate interest and legal obligations.

On the Iris platform (beneficiaries):

• Managing your personal account — identity, work or personal e-mail, employer or organisation, credentials — to create and administer your account, based on the contract (terms of use).

• Prevention questionnaires, scores and recommendations — the answers you declare, including health data (lifestyle, medical history, measurements, how you feel), and calculated scores — to provide you with a personalised check-up and compare it with your previous assessments, based on your explicit consent, collected before each check-up and withdrawable at any time.

• Referral and appointment booking — name, contact details, chosen time slot, reason for the check-up — to organise your check-up with a partner healthcare professional, based on the contract and on your explicit consent for health data.

• Service e-mails — e-mail address — to send you messages essential to the service (invitation, confirmation, password reset, appointment reminders), based on the contract.

• Security, traceability and service quality — login logs, IP address, timestamps — based on our legal obligations and our legitimate interest in keeping the service running securely.

• Aggregated indicators for client companies and insurers — anonymised statistics derived from the questionnaires — to steer prevention policies, based on our legitimate interest and that of the client. You may object to this reuse (see below).

Your data is collected directly from you or, for account creation, provided by your employer or organisation. We only process your data for the purposes described above and never use it for advertising.

Anonymised indicators shared with client companies

Your employer or insurer never receives your answers, your scores or any information that could identify you directly or indirectly.

They receive only dashboards made up of aggregated, anonymised indicators, computed only when at least 30 people have responded for each indicator and each segment (site, department, age group, etc.). Below this threshold, the indicator is not produced. This threshold, above the minimum of 10 recommended by the CNIL, rules out any risk of re-identification.

This reuse of your answers for anonymisation and statistical purposes is a separate processing operation to which you have the right to object at any time, free of charge, by writing to dpo@iris-prevention.fr. Objecting has no impact on your access to the prevention check-up.

How long do we keep your data?

Visitors and prospects:

• Contact and demo form data: 3 years from your last contact.

• Newsletter e-mail address: until you unsubscribe.

• Audience statistics: anonymous, aggregated data kept for a maximum of 25 months.

• Technical and security logs: 1 year.

Iris platform beneficiaries:

• Identification and account data: for as long as the service is made available by your employer or organisation, then archived for the standard limitation period (5 years) before deletion.

• Questionnaire answers, scores and recommendations: kept in the active database while your prevention check-up is being handled and to allow comparison with your subsequent assessments, then for 5 years from your last check-up, for evidentiary purposes (standard limitation period). They may be deleted earlier at the client company's request at the end of the contract, or at your request at any time.

• Appointment data: until the check-up has taken place, then 5 years together with the pathway data.

• Login logs: 1 year.

France Surgery does not create medical records and does not provide medical follow-up: the 20-year retention rule for health records applies to the partner healthcare professionals you consult, not to France Surgery.

Once these periods expire, deletion of your data is irreversible. We may only keep anonymised data for statistical purposes. In the event of litigation, strictly necessary data may be kept until the proceedings are concluded.

Who can access your data?

Your data is accessible only to those who need it to provide you with the service:

• France Surgery's authorised staff, bound by confidentiality and a strict access-rights policy;

• partner healthcare professionals, only when you book an appointment with them and to the extent needed to prepare your check-up;

• our technical service providers, acting as processors on our instructions: Claranet (HDS-certified hosting of the platform), OVH (hosting of the website and CMS), the online appointment booking tool, and our transactional e-mail providers.

We vet all our providers before engaging them and govern each relationship with a data processing agreement compliant with Article 28 GDPR, which imposes the same obligations on their own sub-processors.

We never sell, rent or transfer your data to third parties or commercial partners. Your data may be disclosed to competent authorities where the law requires it.

Does your data leave France?

Data processed for the iris-prevention.fr website and the Iris platform is hosted exclusively on servers located in France, with French hosting providers (Claranet, certified Health Data Hosting provider, and OVH). It is not transferred outside the European Union as part of our services, including when you access the service from abroad.

Should a third-party tool with servers outside the European Union ever be used, we would ensure it offers the appropriate safeguards required by the GDPR (adequacy decision, European Commission standard contractual clauses) and that no health data is transmitted to it.

How do we protect your data?

We implement technical and organisational measures suited to the sensitivity of health data to keep it secure and guard against any risk of destruction, loss, alteration, unauthorised access or disclosure.

Technical measures:

• platform hosted by an HDS-certified provider, in France;

• encrypted communications (HTTPS) and database encryption at rest;

• strong authentication (two-factor) and mandatory complex passwords, for users and administrators alike;

• automatic logout after a period of inactivity;

• access traceability and logging;

• regular penetration testing;

• antivirus, firewall and anti-spam on workstations;

• business continuity and disaster recovery plans.

Organisational measures:

• information security policy and IT charter;

• access-rights and password management policy;

• data breach management procedure and data subject rights procedure;

• staff awareness and training twice a year;

• physical security of premises (badges, alarm, locked offices, video surveillance).

In the event of a data breach likely to result in a high risk to your rights and freedoms, we will inform you as required by the GDPR and notify the CNIL within 72 hours.

Do we use cookies?

We guarantee that we use no advertising cookies, no tracking cookies and no social media cookies on the iris-prevention.fr website.

Website audience measurement is performed with Umami, a tool self-hosted on our own servers that sets no cookie or tracker on your device, collects only aggregated, anonymous data and does not track you across websites. It falls under the CNIL's consent exemption for audience measurement; you may nevertheless object by writing to dpo@iris-prevention.fr.

The Iris platform uses only cookies strictly necessary for its operation (session, authentication, security), which are exempt from consent. They are deleted when you close your session or when the login period expires.

What are your rights?

The law grants you rights that you can exercise at any time, free of charge:

• Right of access to and a copy of your data, provided the request does not undermine trade secrets, confidentiality or the secrecy of correspondence.

• Right to rectification of inaccurate, outdated or incomplete data.

• Right to erasure (“right to be forgotten”), within the limits of our legal retention obligations.

• Right to restriction of processing, which freezes the use of your data in the event of a dispute.

• Right to object to processing based on our legitimate interest, in particular the production of anonymised indicators, and to any direct marketing.

• Right to withdraw your consent at any time, in particular to the processing of your health data, without affecting the lawfulness of processing already carried out.

• Right to data portability, to retrieve your data in a structured, commonly used format.

• Right to give instructions regarding your data after your death.

To help us handle your request, send it directly to dpo@iris-prevention.fr or by post to France Surgery — DPO, 11 rue Saint-Expédit, 31500 Toulouse, France. If we have doubts about your identity, we may ask for proof. You may be represented; we may then request proof of authority.

We will reply as soon as possible and at the latest within one month, extendable by two months for complex requests or a high volume of simultaneous requests. We may refuse to act on requests that are manifestly unfounded or excessive, in particular because of their repetitive nature.

Who can you contact for more information?

To best protect your data, France Surgery has appointed an independent Data Protection Officer (“DPO”), DIPEEO, registered with the CNIL under no. DPO-161280 since 22 May 2025.

You can contact our DPO at any time, free of charge:

• by e-mail: dpo@iris-prevention.fr

• by post: France Surgery — DPO, 11 rue Saint-Expédit, 31500 Toulouse, France.

How can you contact the CNIL?

If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the French data protection authority (CNIL): Service des plaintes, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — +33 1 53 73 22 22 — www.cnil.fr.

Can this policy change?

We may amend this policy at any time to reflect new legal requirements, CNIL recommendations and any new processing we may implement. The applicable version is the one published on this page; the last update date appears at the top of the document. In the event of a substantial change affecting the processing of your health data, you will be informed at your next login to the platform.

Policy drawn up with the support of our DPO, Dipeeo.