Latest amendments on 21 October 2021

Detailed below is the Confidentiality Policy for the website, owned by the EDHEC Association (a not-for-profit association under France’s Law of 1901) – 24 Avenue Gustave Delory (CS 50411), 59057 Roubaix Cedex, France.

I – Identity and contact details of the Data Controller

The EDHEC Association (a not-for-profit association under France’s Law of 1901) – 24 Avenue Gustave Delory (CS 50411), 59057 Roubaix Cedex, France – is the Data Controller.

II – Purposes of processing 

Your personal data is processed when:

You wish to access the Alllmyindex scoring service, a web platform that assesses the degree of transformation of legal departments on different transformation themes (innovation, digitalisation, etc.) by means of indices (scores).

Processing may vary according to the services in question:

  • Access to the services offering (legal transformation score, improvement plan and certification)
  • Registration for the “Alllyouneed” newsletter and other information e-mails sent from the website, in order for you to receive information, details on good practices and commercial offers from the EDHEC Augmented Law Institute related to the training and career development of lawyers.

You will also find our cookie policy.

III – Legal basis for data processing 

  1. Concerning services, the legal basis for processing for all users is the consent gathered via the tick box provided for this purpose on the registration form (opt-in)
  2. Concerning the Alllyouneed newsletter and the e-mails addressed to law professionals, the legal basis for processing is the consent alleged by the box pre-ticked for this purpose on the registration form (opt-out)


IV – Collected data

1. Concerning AlllmyIndex services

The following mandatory data items are requested:

  • Online questionnaire for obtaining a legal transformation score
    • Last name
    • First name(s)
    • E-mail address
    • Size of company
    • Sector of activity
    • Size of legal team
    • Country

2. Concerning the Alllyouneed newsletter 

Mandatory data

  • Registration as a member of the newsletter
    • E-mail address

V – Data recipients or categories of data recipients

The main recipient of the data is the Data Controller: EDHEC.

Not-for-profit association under France’s Law of 1901 – 24 Avenue Gustave Delory (CS 50411) 59057, Roubaix Cedex, France

EDHEC also works with DIGITDAYS in the latter’s capacity of technical service provider to develop and manage the platform.

EDHEC also stores data on its MailChimp account for the purposes of sending newsletters and commercial emailings.

EDHEC also stores data on its SurveyAnyplace account for permitting users to come back to the survey later by receiving a weblink by email.

Therefore, in relation to this mission,

EDHEC has satisfied itself that the processing performed by DIGITDAYS and Mailchimp complies with the GDPR.

EDHEC has satisfied itself that DIGITDAYS and MailChimp have put in place measures with regard to the sensitivity of the data processed, so as to ensure its security and to notably avoid its disclosure to non-authorised third parties.

VI – Data retention period

The personal data of user accounts is retained for 36 months (3 years) after the last activity recorded on the account. After this period, the account is considered to be inactive. The user’s consent is then requested prior to erasure of the data.

Session cookies are retained for the time the user is connected. They are deleted when the visitor closes their browser.

VIII – Rights of data subjects

Any registration on website is subject to your prior acceptance of the Confidentiality Policy, by ticking the “I have read and agree to the Confidentiality Policy” box.

By ticking this box, you acknowledge that you have read, understood and agreed to this Policy in full.
EDHEC reserves the possibility of adapting or amending it any time, while promising to notify you when doing so.

Concerning amendments made to the Policy that have consequences for the processing of your personal data, EDHEC agrees to gather your renewed consent.

In the event of subsidiarisation or merger/acquisition of the website, EDHEC shall give you prior notice of the operation and the transmission of your personal data to the new entity; consequently, EDHEC shall merely notify you, but will not request your renewed consent.

You possess rights over your personal data.

You have the right:

  • to withdraw your consent at any time
  • to object to the processing of your data if the processing is performed on a legal basis other than that of consent
  • to access your data. You have the right to know which items of data are processed and to obtain a copy thereof
  • to obtain the rectification of incorrect or incomplete data that concerns you. You have the right to obtain the accuracy of your data and to request that it is updated or corrected
  • to restrict processing of your data. In this case, EDHEC will have this data processed solely in order to store it. You have the right to obtain the restriction of processing of your personal data held by EDHEC if:
    • you contest the accuracy of the information (exercise of the right of rectification) concomitantly with your request to restrict processing
    • the processing is unlawful and you object to the erasure of the data and request restriction of its use instead
    • you object to processing (exercise of the right to object) and you exercise your right to restrict processing pending the verification conducted in order to determine whether the legitimate grounds of the data controller override those of the data subject
    • EDHEC no longer needs the personal data collected in relation to the purpose of processing, but the data is still necessary for you to establish, exercise or defend legal claims
  • to have your personal data erased. You have the right to obtain the erasure of your personal data held by EDHEC if:
    • the data is no longer necessary in relation to the purposes for which it was collected
    • you have withdrawn your consent on which the processing was based and there is no other legal ground for processing
    • you object to the processing of the data and there are no overriding legitimate grounds for processing
    • the data has been unlawfully processed
    • the data has to be erased for compliance with a legal obligation in EU or Member State law to which EDHEC is subject
    • or the data concerns a child aged under 16
  • portability of your data. You have the right to receive your data in a commonly used machine-readable format, in order to then store it yourself or transfer it to a third party. This measure applies on condition that the data is processed by automatic means and that the processing is based on your consent, on a contract to which you are party or on pre-contractual obligations.
  • to file a complaint with the supervisory authority competent in the area of personal data.

IX – Data Protection Officer’s contact details

If you wish to exercise one of these rights, you may contact the Data Controller’s Data Protection Officer (DPO) at the following address:

X – Right to complain to the CNIL (French data protection authority)

If you consider that after contacting our DPO, your rights on your data have not been upheld, you may send a complaint to the CNIL (