Personal Data Protection Policy

DPDgroup Privacy DPDgroup Privacy

Geopost is committed to personal data protection both during our business operations and as part of the services provided.

This Policy sets out the principles and guidelines we apply to protect your Personal Data. It is designed to explain:

  • The types of Personal Data we collect and the reasons why we collect it,

  • How we use your Personal Data,

  • Your rights as the data subject.

 

This Policy applies to the processing of Personal Data in the context of Geopost's parcel delivery activities in an international context. All operations on your Personal Data are carried out in compliance with the regulations in force and in particular with the European Regulation (EU) 2016/679 of 27 April 2016 on the protection of personal data (GDPR), the law n°78-17 "Informatique, Fichiers et Libertés" of 6th January 1978 as amended, as well as its application decrees.

 

Further personal Data Protection information

How does Geopost deal with Personal Data Protection?

Geopost considers the protection of your Personal Data and privacy when designing new products and services (principles of "privacy by design" and "privacy by default"), and where appropriate, when these products or services are revised/upgraded. To ensure the security of your Personal Data and safeguard the proper exercise of your rights, Geopost implements measures designed to protect your Personal Data :

 - Establishment of a procedure for exercising rights and a procedure in the event of a personal data breach;

- Carrying out IT security and GDPR compliance questionnaires prior to the implementation of a project or an application;

- Verification of the guarantees presented by our subcontractors and future subcontractors with regard to the requirements of the GDPR;

- Carrying out internal audits, drawing up recommendations, monitoring and updating the inherent actions;

- Consulting with project managers to define relevant and reasonable retention periods, not exceeding the time necessary to fulfil the purpose of the processing;

- Maintaining and updating a register of processing operations;

- Conducting regular training sessions for all our employees;

- Coordination of a Data Protection Officer network including all our European subsidiaries

 

What Personal Data are used by Geopost?

Geopost undertakes to only collect the data that is strictly necessary for the provision of the requested services.

If optional data is requested, you will be given a clear explanation of the Personal Data Geopost needs to provide the requested service and the data you may decide to provide voluntarily.

Where does the data we process come from?

If you ship a package, we receive your data when you contact us, visit one of our shipping sites or ship packages with us.

If you are the recipient of a package, we receive your data from our shipping customers. They provide us with your data, together with package information or notification instructions, primarily in electronic form or via their own or our shipping systems. They normally do this to the extent that they have established a contractual relationship with you in accordance with Article 6(1b) of the GDPR, and we need this data to deliver the goods you have ordered to the shipper. In addition, we naturally receive your data from other postal service providers who act on our behalf for the delivery of consignments, for example if the consignment originates from abroad and another postal service provider who cooperates with us has been commissioned with the delivery.

Finally, we receive data directly from you when you have filled in your personal information in your user area (delivery address, delivery preferences, etc.).

If you are a visitor to our website, we receive your data through various functions of the website. For this purpose we use cookies or ask you directly for information. Our priority is to optimise the presentation of our website and to provide you with information about our services. You can limit the services or disable them completely at any time by using a link or by making the appropriate selection. (Please see "Web analysis, cookies and advertising services").

Your Personal Data will only be used to propose other services if you have agreed to receive commercial communication. In any case, you have the possibility to revoke your consent at any time.

To which services or companies are your Personal Data transferred to?

Your data may be transferred to:

  • Departments within Geopost: departments in charge of performing the requested services;

  • External providers: technical service providers, including sub-contractors (if applicable, the data is transmitted to our subcontractors under the conditions prescribed by Article 28 of the GDPR);

  • Companies of La Poste Group, for the performance of the services.

Can your Personal Data be transferred to non-EU countries?

Geopost carries out all Personal Data processing activities within the European Union (EU).

However, for some specific services, Geopost may use data processors or business partners located outside of the EU. Some of your Personal Data may therefore be transferred to them for the strict purposes of their services. In such cases and in accordance with the regulations in force, Geopost requires its data processors to provide the necessary safeguards to ensure regulated, secure transfers, mainly by requiring them to sign the European Commission’s standard contractual clauses.

How long will Geopost keep your Personal Data?

Different retention periods apply for the various services we provide. Geopost undertakes not to retain your Personal Data any longer than is necessary for the provision of the service or, if applicable, for compliance with the retention periods arising from the applicable limitation periods.

Joint Controllership

For the implementation of the processing of personal data described, Geopost determines, jointly with its subsidiaries located on the territory of the European Union or in a country recognised as adequate by the European Commission, the purposes and means of the processing. In accordance with Article 26 of the GDPR, a joint data controller agreement has been signed by all the data controllers concerned. It describes in particular the responsibilities and obligations of each of the joint controllers, the relations with the data subjects and the way in which the latter can exercise their rights with regard to the GDPR, the security and confidentiality measures taken to protect their personal data, the defined retention periods (these may however vary locally in application of the regulations in force), as well as the procedure in the event of detection of a data breach.

Personal data processing

Common Processing Activity

Agreed purposes

Legal basisPersonal DataRetention period
CS Investigation & claim management• Customer service back-office communication tool between customer services of BUs for cross-border parcels • Measurement of BU's performance • Monitoring the performance of BU’s customer service employees by managers of BU’s CSPerformance of a contract (for claim management) + Legitimate interest (for the measurement of BU's performance)Sender or receiver data, when is Consumer only: Name, address (street number, zip code, city, country) e-mail, phone number, parcel number, collection request number, case number, COD amount, POD, free text fields for parcel content for example6 months after case closure database and 6 months in archive database (not anonymized) Anonymization of consignee’s personal data for reporting
Parcel delivery & unauthenticated consignee interaction

- Shipment and labeling process - Track and trace by Geopost employees - Consultation of the parcel’s status by customers via dedicated applications - Delivery tool management - Order management / collection requests - Parcel’s temperature (containing food) monitoring throughout their life cycle and generate alerts in the event of a break in the cold chain - Calculation of an estimated number of days to deliver parcel based on zip code of both the origin and the destination - Facilitating delivery services with delivery instructions - Track and trace the parcels by the consignees via consignee application - Knowledge improvement and interaction with consignees and prospects - Parcel return management - Collection of the level of satisfaction of the consignees

Performance of a contract + Legitimate interest + Legal obligationSender or receiver data, when is Consumer only: First / last name, username, e-mail, address (including home GPS coordinates), phone number, parcel number, date of birth, home GPS coordinates, POD, picture of front door or safe place, COD, contact details, ID numbers, additional information necessary for ID check, free text fields for more detail about the address for example (door code) Depending on BUs, some other personal data can be stored and managed locally.

6 months in active database + archive database for regulatory purposes (indicated in other processing)

Postal address (House number, street name, city, Post code, Country code, Longitude, Latitude) will be kept for 3 years based on the necessity to have reliable data and be able to calculate tactical planning scenarios).

Geocheck (Embargo)- Comparison of personal data against Denied Party Lists (DPLs) published by organizations - Generation of events according to verification results - Decision whether or not to block the parcel - Request of licenses if designated persons are confirmed among the workforceLegal obligationReceiver data, when is Consumer only: Name, e-mail, address, phone number, parcel number, result of the comparison/verification These personal data concerns also the employees of DPDgroup.30 days in live/production database From 30 days to 2 years on a restricted database (restricted access for LECO only) From 2 years to 10 years in archive (legal requirements, restricted access only for Geocheck administrator)
Customs process- Notification management and payment for duties and taxes - Generation of proofs of paymentLegal obligationSender and receiver data, when is Consumer only: Name, e-mail, address (including street and house number, city, country, zip code), phone number, SMS, contact, parcel number, IP address, content of the parcels associated to value of goods6 months in active database and 5 years in archive database (unless advised differently by BUs)
Reporting KPI- Leverage data from X months/years for sales/marketing/ops analysis for market assessment - Measurement of the quality of the performanceLegitimate interestSender and receiver data, when is Consumer only: Name, e-mail, address, phone number, parcel number6 months (anonymization after) Postal address (House number, street name, city, Post code, Country code, Longitude, Latitude) will be kept for 3 years based on the necessity to have reliable data and be able to calculate tactical planning scenarios)
Authenticated consignee interaction

- Management of notifications to consignees via e-mail or SMS or social media (Predict, etc.) - Execution of prospecting operations to improve the offers and services of Geopost and its subsidiaries - Collection of the level of satisfaction of the consignees - Consumers profiling according to uses of Geopost services, frequency of delivery, delivery experiences and customer service interactions, etc. (without automated decisions) - Display of advertising, newsletters, personalized campaign - Loyalty program

Performance of a contract + Legitimate interest + ConsentSender and receiver data, when is Consumer only: Name, e-mail, address, phone number, parcel number Sender and receiver data, when is Consumer only: Name, e-mail, address (street, street number, house number, postcode, city), phone number, parcel number, title (Mr, Ms), company, free text fields, ID numbers and passports, HS code, login, gender, delivery preferences (preferred PUDO location, safeplace, etc.), communication preferences (email, SMS, push, etc) Data may concern also 3rd person and/or neighbor who retrieve the parcel instead of the consignee2 years following last connection Postal address (House number, street name, city, Post code, Country code, Longitude, Latitude) will be kept for 3 years based on the necessity to have reliable data and be able to calculate tactical planning scenarios)
Export Control

Allow Geopost and its subsidiaries to verify export authorisations and permits for dual-use goods

Legal obligation- Name, First name - Postal address - Parcel content (HS code and description) - Origin country of the parcel - Destination country of the parcel - Telephone number30 days in a live/production database - 30 days to 2 years on a restricted database (restricted access only for LECO - Local Embargo Compliance Officer) - 2 years to 6 years in archives (legal requirements, restricted access only for ECM administrator
Professionnal whistleblowing / Safecall- Receiving and recording whistleblowing alerts - Investigation and monitoring of the alerts - Closure of alerts - Development of activity data (statistics) on anonymous dataLegal obligation Legitimate interest- Email address - Date and purpose of whistleblowing alert - Phone number - First name, last name - Any other data communicated as part of the alert and/or investigationRelevant data to process the whistleblowing shall be kept during the processing. If the alert: - is not eligible, data anonymized within 30 days of receipt. - is admissible but not reasoned or does not give rise to disciplinary/legal action, it is anonymised within 2 months of its closure. - gives rise to disciplinary or legal actions, the data are kept until the end of the actions or measures and are anonymized within 2 months, unless legal obligations impose another retention period

Agreed purposes

CS Investigation & claim management• Customer service back-office communication tool between customer services of BUs for cross-border parcels • Measurement of BU's performance • Monitoring the performance of BU’s customer service employees by managers of BU’s CS
Parcel delivery & unauthenticated consignee interaction

- Shipment and labeling process - Track and trace by Geopost employees - Consultation of the parcel’s status by customers via dedicated applications - Delivery tool management - Order management / collection requests - Parcel’s temperature (containing food) monitoring throughout their life cycle and generate alerts in the event of a break in the cold chain - Calculation of an estimated number of days to deliver parcel based on zip code of both the origin and the destination - Facilitating delivery services with delivery instructions - Track and trace the parcels by the consignees via consignee application - Knowledge improvement and interaction with consignees and prospects - Parcel return management - Collection of the level of satisfaction of the consignees

Geocheck (Embargo)- Comparison of personal data against Denied Party Lists (DPLs) published by organizations - Generation of events according to verification results - Decision whether or not to block the parcel - Request of licenses if designated persons are confirmed among the workforce
Customs process- Notification management and payment for duties and taxes - Generation of proofs of payment
Reporting KPI- Leverage data from X months/years for sales/marketing/ops analysis for market assessment - Measurement of the quality of the performance
Authenticated consignee interaction

- Management of notifications to consignees via e-mail or SMS or social media (Predict, etc.) - Execution of prospecting operations to improve the offers and services of Geopost and its subsidiaries - Collection of the level of satisfaction of the consignees - Consumers profiling according to uses of Geopost services, frequency of delivery, delivery experiences and customer service interactions, etc. (without automated decisions) - Display of advertising, newsletters, personalized campaign - Loyalty program

Export Control

Allow Geopost and its subsidiaries to verify export authorisations and permits for dual-use goods

Professionnal whistleblowing / Safecall- Receiving and recording whistleblowing alerts - Investigation and monitoring of the alerts - Closure of alerts - Development of activity data (statistics) on anonymous data
Legal basis
CS Investigation & claim managementPerformance of a contract (for claim management) + Legitimate interest (for the measurement of BU's performance)
Parcel delivery & unauthenticated consignee interactionPerformance of a contract + Legitimate interest + Legal obligation
Geocheck (Embargo)Legal obligation
Customs processLegal obligation
Reporting KPILegitimate interest
Authenticated consignee interactionPerformance of a contract + Legitimate interest + Consent
Export ControlLegal obligation
Professionnal whistleblowing / SafecallLegal obligation Legitimate interest
Personal Data
CS Investigation & claim managementSender or receiver data, when is Consumer only: Name, address (street number, zip code, city, country) e-mail, phone number, parcel number, collection request number, case number, COD amount, POD, free text fields for parcel content for example
Parcel delivery & unauthenticated consignee interactionSender or receiver data, when is Consumer only: First / last name, username, e-mail, address (including home GPS coordinates), phone number, parcel number, date of birth, home GPS coordinates, POD, picture of front door or safe place, COD, contact details, ID numbers, additional information necessary for ID check, free text fields for more detail about the address for example (door code) Depending on BUs, some other personal data can be stored and managed locally.
Geocheck (Embargo)Receiver data, when is Consumer only: Name, e-mail, address, phone number, parcel number, result of the comparison/verification These personal data concerns also the employees of DPDgroup.
Customs processSender and receiver data, when is Consumer only: Name, e-mail, address (including street and house number, city, country, zip code), phone number, SMS, contact, parcel number, IP address, content of the parcels associated to value of goods
Reporting KPISender and receiver data, when is Consumer only: Name, e-mail, address, phone number, parcel number
Authenticated consignee interactionSender and receiver data, when is Consumer only: Name, e-mail, address, phone number, parcel number Sender and receiver data, when is Consumer only: Name, e-mail, address (street, street number, house number, postcode, city), phone number, parcel number, title (Mr, Ms), company, free text fields, ID numbers and passports, HS code, login, gender, delivery preferences (preferred PUDO location, safeplace, etc.), communication preferences (email, SMS, push, etc) Data may concern also 3rd person and/or neighbor who retrieve the parcel instead of the consignee
Export Control- Name, First name - Postal address - Parcel content (HS code and description) - Origin country of the parcel - Destination country of the parcel - Telephone number
Professionnal whistleblowing / Safecall- Email address - Date and purpose of whistleblowing alert - Phone number - First name, last name - Any other data communicated as part of the alert and/or investigation
Retention period
CS Investigation & claim management6 months after case closure database and 6 months in archive database (not anonymized) Anonymization of consignee’s personal data for reporting
Parcel delivery & unauthenticated consignee interaction

6 months in active database + archive database for regulatory purposes (indicated in other processing)

Postal address (House number, street name, city, Post code, Country code, Longitude, Latitude) will be kept for 3 years based on the necessity to have reliable data and be able to calculate tactical planning scenarios).

Geocheck (Embargo)30 days in live/production database From 30 days to 2 years on a restricted database (restricted access for LECO only) From 2 years to 10 years in archive (legal requirements, restricted access only for Geocheck administrator)
Customs process6 months in active database and 5 years in archive database (unless advised differently by BUs)
Reporting KPI6 months (anonymization after) Postal address (House number, street name, city, Post code, Country code, Longitude, Latitude) will be kept for 3 years based on the necessity to have reliable data and be able to calculate tactical planning scenarios)
Authenticated consignee interaction2 years following last connection Postal address (House number, street name, city, Post code, Country code, Longitude, Latitude) will be kept for 3 years based on the necessity to have reliable data and be able to calculate tactical planning scenarios)
Export Control30 days in a live/production database - 30 days to 2 years on a restricted database (restricted access only for LECO - Local Embargo Compliance Officer) - 2 years to 6 years in archives (legal requirements, restricted access only for ECM administrator
Professionnal whistleblowing / SafecallRelevant data to process the whistleblowing shall be kept during the processing. If the alert: - is not eligible, data anonymized within 30 days of receipt. - is admissible but not reasoned or does not give rise to disciplinary/legal action, it is anonymised within 2 months of its closure. - gives rise to disciplinary or legal actions, the data are kept until the end of the actions or measures and are anonymized within 2 months, unless legal obligations impose another retention period

Other data processing

For the data processing described below, Geopost SA is data controller and determines the means and purposes of the processing.

Common Processing ActivityPurposesLegal basisPersonal DataRetention period
GATE – Business management- Client and prospect management - Development of trade statistics - Steering and monitoring the activity of the sales team- Performance of a contract (for Customers) - Legitimate interest (for prospects)- Name, First name - Email - Phone number - Job qualificationThe personal data are kept during the contractual relationship for the Customers. The data are kept for a period of 3 years from the last contact with the data subjects when it comes to prospects. After the performance of the contract, the data are kept in intermediate storage, if the controller has the legal obligation to do so (for example, to meet accounting or tax obligations) or if he wishes to establish evidence in the event of litigation and within the applicable limitation period
Purposes
GATE – Business management- Client and prospect management - Development of trade statistics - Steering and monitoring the activity of the sales team
Legal basis
GATE – Business management- Performance of a contract (for Customers) - Legitimate interest (for prospects)
Personal Data
GATE – Business management- Name, First name - Email - Phone number - Job qualification
Retention period
GATE – Business managementThe personal data are kept during the contractual relationship for the Customers. The data are kept for a period of 3 years from the last contact with the data subjects when it comes to prospects. After the performance of the contract, the data are kept in intermediate storage, if the controller has the legal obligation to do so (for example, to meet accounting or tax obligations) or if he wishes to establish evidence in the event of litigation and within the applicable limitation period

Are your Personal Data protected?

Geopost undertakes to adopt all measures protecting the security and confidentiality of your Personal Data and, in particular, to prevent any damage, erasure or unauthorised access by a third party.

To this end, Geopost has an Information System Security Policy based on the ISO 27002 standard, which defines the guidelines for good information security management practices. The policy covers human, physical, organisational and technical security controls.

If your Personal Data is affected by a security breach (destruction, loss, alteration or disclosure), Geopost undertakes to fulfil our obligation to notify Personal Data Breaches, in particular to the French Data Protection Authority (CNIL) and to inform you as soon as possible in accordance with Article 34 of the GDPR.

What are your rights concerning your Personal Data?

You may contact Geopost to exercise your rights held under the personal data regulations in force at any time:

  • Right of access: you may obtain a copy of your Personal Data being processed by Geopost;

  • Right to rectification: you may update your Personal Data or ask us to rectify your Personal Data processed by Geopost;

  • Right to object, in particular to prevent direct marketing: you may notify your preference not to receive direct marketing from Geopost or ask Geopost to stop processing your Personal Data;

  • Right to erasure: you may ask Geopost to delete your Personal Data;

  • Right to restrict processing: you may ask Geopost to suspend the processing of your Personal Data;

  • Right to data portability: you may ask Geopost to retrieve your Personal Data for reuse.

 

Whenever you sign up for a service or provide Personal Data, Geopost will state the postal and/or email address to which any data subject requests may be sent.

All requests must be submitted with proof of your identity. Geopost undertakes to respond to your data subject requests without undue delay and in any event, within the times imposed by law.

Has Geopost appointed a Data Protection Officer?

The appointment of a Data Protection Officer reflects Geopost’s commitment to ensuring the protection, security and confidentiality of Personal Data.

Our Data Protection Officer may be contacted at the following address:

Data Protection Officer

CP C703

9 Rue du Colonel Pierre Avia

75015 Paris

 

If you believe, after having contacted us, that your rights with regard to your data have not been respected, you may submit a complaint to the Commission Nationale de l'Informatique et des Libertés (3 place de Fontenoy - TSA 80715 - 75334 Paris cedex 07; tel: 01 53 73 22 22).

 

Cookies and third-party services

We and our partners use cookies or other tracers to facilitate the use of the site, improve the performance and security of the site, and propose personalized advertising according to your use and your profile. These cookies, apart from necessary cookies, require your consent before their deposit. Your choices will be valid for the vendors and purposes listed into the “Cookie settings”. You can withdraw your consent at any time by managing your cookies through "Cookies" in our website footer.

Changes to this Privacy policy

Our privacy policy is reviewed on a regular basis.

 

Geopost reserves the right to change its privacy policy at any time with or without prior notice. We therefore recommend that you inform yourself regularly about any changes. By using Geopost website you accept the terms of this privacy policy.

 

Privacy policy last update: April 2023

Chatbot

In several Geopost branches, members of our Geopost network, a chatbot is available to help you track, redirect and get more detailed information about your parcel. Please note that the chatbot includes a free comment area where you may be asked to provide personal data to help us find information about your parcel. This data will be used to review your request and is necessary for us to provide a more appropriate response. The information you provide is sent to our customer service department and our technical service providers in the context of the tasks entrusted to them.

The data collected in the context of a conversation about the delivery of a package is kept for six (6) months, i.e. the life of a package, after which it is automatically deleted. Data can also be deleted in advance upon request. To the extent that information collected in this manner is personally identifiable, it will be processed in accordance with Art. 6 of the GDPR on the basis of our legitimate interest in providing efficient customer service.

In accordance with the applicable regulations on the protection of personal data, you have the right to access, rectify, object to, limit the processing of, request the transfer of your data where possible and delete your data.

We also draw your attention to the importance of not communicating sensitive data (in the sense of article 9 of the GDPR) in this free comment area.

Glossary

All capitalised terms are defined as follows:

“Data Protection Policy”: Means this Policy describing the measures adopted for the processing, exploitation and management of your Personal Data and your data subject rights.

“Personal Data”: Means any information relating to you that can be used to identify you, directly or indirectly as a natural person.

“Processing”: Means any operation or any set of operations performed on your Personal Data.

“Personal Data Breach”: Means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, your Personal Data.

myDPD Privacy Policy

Please select your country to see the relevant Privacy Policy.

Please select your country
DPD Belgium
DPD Croatia
DPD Luxembourg
DPD Portugal
DPD Switzerland