INFORMATION NOTICE FOR AXA GIE, AXA GIE UNIVERSITY, AXA SA AND AXA GLOBAL MOVE EMPLOYEE
AXA respects your privacy and ensures that all personal data it handles is processed in accordance with best confidentiality practices and the applicable laws on data protection, and notably the European Union General Data Protection n°2016/679 (GDPR).
The objective of this Information Notice is to present the several processing of your personal data carried out as an employee of GIE AXA, GIE AXA University, AXA SA or AXA Global Move.
Update of the present notice on the protection of your personal data
The Data Controllers (as defined below) may update this Information Notice from time to time in response to changing legal, technical, or business developments. When the Data Controllers update this Information Notice, the Data Controllers will take appropriate measures to inform you, consistent with the significance of the changes the Data Controllers make. The Data Controllers will obtain your consent to any material Notice changes if and where this is required by applicable data protection laws. This Information Notice was last updated on January 9th, 2025.
Table of contents
Update of the present notice on the protection of your personal data
Who are the Data controllers of your personal data?
What are your rights to your personal data?
How to contact the DPO or exercise your rights?
How to make a complaint to a Supervisory Authority?
How do we ensure the security of your personal data?
Is the provision of your personal data mandatory?
For what purposes and in what way is your personal data processed?
What about Secure GPT and My AI Brain?
Is an automated decision made in the context of this processing?
Where do your personal data come from?
To whom do we disclose your personal data?
Is your personal data transferred outside the European Union (EU)?
Who are the data controllers of your personal data?
GIE AXA, a European Economic Interest Grouping, organized under French law, with its registered office at 23 Avenue Matignon, 75008 Paris, registered with the Registry of Commerce and Companies of Paris under the number 333 491 066, can act as an independent data controller (it determines the purposes and means of the processing of your information).
GIE AXA and AXA SA (AXA SA, a Société Anonyme, organized under French law, with its registered office at 25 Avenue Matignon, 75008 Paris, registered with the Registry of Commerce and Companies of Paris under number 572 093 920, excluding these subsidiaries), or GIE AXA and GIE AXA Université (a European Economic Interest Grouping, organized under French law, with its registered office at 23 Avenue Matignon, 75008 Paris, registered with the Registry of Commerce and Companies of Paris under the number 342 312 931) or GIE AXA and AXA Global Move, Société Anonyme organized under Swiss law, with its registered office at Route des Acacias 47, 1227 Les Acacias, Case Postale 1510, 1211 Genève 26 (Suisse), registered with the Registry of Commerce IDE under the number CHE-158.210.029 can act as joint data controllers (they jointly determine the purposes and means of the processing of your information).
The data controllers are referred to in this Notice as "AXA" or "Data Controllers" or "We" or "Us".
What are your rights to your personal data?
In accordance with the French "Informatique et Libertés" law n° 78-17 of 6 January 1978 and the GDPR, you have the right to:
Access to your personal data: you have the right to request access to the personal data We process about you, and to obtain a copy of that data,
Rectify your personal data: you have the right to ask AXA to rectify or complete the personal data that We process about you that are inaccurate, incomplete, or not up to date,
Request the limitation of the processing of your personal data: you have the right to ask AXA to limit the processing of your personal data. This means that the Data Controllers may simply keep your data but may not process or use it in any other way,
Decide what happens to your personal data after your death: you have the right to give AXA instructions as to how your personal data should be used after your death.
Based on the legal basis for the processing of your personal data described in the table below, you have also the right to:
Request the deletion of your personal data: you have the right to ask AXA to delete your personal data, except where the processing is based on the performance of a legal obligation of the Data Controllers,
Right to portability of your personal data: you have the right to receive the personal data you have provided to Us in a suitable format and have the right to transfer that data to another data controller without Us interfering but only where the processing is based on the performance of a contract or your consent,
Withdraw your consent at any time by contacting the DPO at the following address: privacy@axa.com, but only where the processing of your personal data is based on your consent.
You also have the right to object at any time, where the processing of your personal data is based on the Data Controllers' legitimate interest(s), (please refer to the below table describing the legal basis for the processing of your personal data) to the processing of your personal data, unless the Data Controllers can demonstrate the need for further processing or where such data is necessary for the establishment, exercise, or defense of legal claims.
Furthermore, information on the balancing test can be obtained on request by contacting the following address: privacy@axa.com
How to contact the DPO or exercise your rights?
If you have any questions, complaints, or comments regarding this Information Notice or to exercise your rights listed above, please contact the DPO. The contact details are as follows: (i) privacy@axa.com and/or (ii) 23 avenue Matignon, 75008, Paris for GIE AXA or 25 avenue Matignon, 75008, Paris for AXA SA.
The Data Controllers may ask you for additional information to confirm your identity and/or to assist AXA to locate the data youare seeking
How to make a complaint to a supervisory authority?
You have the right to raise concerns about how your personal data is being processed with a competent supervisory authority, in the Member State of your habitual residence, place of work or place where you think an alleged infringement to your rights occurred.
In France, the data protection authority is the Commission Nationale de l'Informatique et des Libertés, or “CNIL” whose postal address is 3 place de Fontenoy - TSA 80715 – 75334 Paris CEDEX 07. Its website is accessible here: https://www.cnil.fr/
How do we ensure the security of your personal data?
The Data Controllers use appropriate technical and organizational measures designed to protect the personal information about you. The measures the Data Controllers use are designed to provide a level of security appropriate to the risk of the processing activity of your personal information, in line with AXA standards.
Is the provision of your personal data mandatory?
Whether or not the provision of your personal data to AXA is mandatory will be indicated to you at the time of collection of such data (e.g., by an asterisk on the collection form). If you do not provide AXA with personal data identified as mandatory, AXA may be unable to manage properly your recruitment, administrative management of personnel, trainings, management of employees share ownership, controls, statistics and data quality, management of press, newsletter and events processing that concern you as an employee.
For what purposes and in what way is your personal data processed?
Your personal data are processed for the different purposes listed in the table below.
Please refer to the following categories to know the different purposes of your personal data processing but also the legal basis chosen, the categories of personal data processed, and the data retention period applied.