DATA PRIVACY POLICY
Effective Date: 25 May 2018
Protecting your personal data is a priority for Malt.
This Data Privacy Policy describes how Malt processes the personal data of Users and visitors to the Site. In particular, our aim is to inform you about:
What data we process, for what purposes and on what basis
How AI is used at Malt
Our cookies policy
Recipients and transmission of data
Data security
Your rights
We undertake to only gather the data required to ensure you receive the best possible service, to protect its confidentiality and security - including when we call on service providers - and to facilitate your ability to exercise your rights over your data. This is done in compliance with the data protection laws in force within all the countries where we operate, including and not limited to, the General Data Protection Regulation 2016/679 ("GDPR"), the United Kingdom Data Protection Act 2018 ("UK GDPR"), the Swiss Federal Data Protection Act of 25 September 2020 ("nLPD"), the Saudi Arabian Data Protection Act of 24 September 2021 ("PDLP"), the Federal Law Concerning the Protection of Personal Data in the United Arab Emirates of 2 January 2 2022 ("FDPL").
Capitalized terms have the meaning set forth in Malt's Terms and Conditions of Use and Sale (T&C), which can be accessed by following this link: https://en.malt.fr/legal.
Data controller: Malt Community
The terms "Malt", "we", or "us" refer to the Company Malt Community SA, registered in the Paris Trade and Companies Register under number 791 354 871, whose registered office is located at 18 rue Godot de Mauroy, 75009 Paris, and its subsidiaries as identified in the T&C, all of which are subject to the same level of data protection.
Contact details of our DPO
If you have any questions about data protection at Malt, or if you wish to exercise your rights, please contact our Data Protection Officer:
by email to [email protected]
by post to: Malt Community, DPO, Malt Community, 18 rue Godot de Mauroy, 75009 Paris.
Effective date and amendments
This Data Privacy Policy automatically takes effect for all Users as of 25 May 2018.
We reserve the right to modify this Data Privacy Policy at any time. The most current version of the Policy governs your use of your data and will be kept available at: https://en.malt.fr/about/privacy/policy.
Should we make any substantial changes to this privacy policy, you will be notified via email at the address provided when you signed up.
If you continue to use the Marketplace or visit the Site after these changes have been made, you will be deemed to have accepted these changes.
1. What data we process, for what purposes and on what basis
In general, we use your data to provide you with our Services as defined in the T&C. We may process certain data with your consent for legitimate reasons or in compliance with a legal obligation.
Data source: Freelancer
We process various types of personal data pertaining to you:
Personal information: surname, first name, place and date of birth, nationality - and official national identification number, if applicable - telephone number, email address, location, profile photo, language
Professional information: legal status and structure, legal documents, VAT number, identity of the company's legal representative, past professional experience and CV, portfolio, Assignment preferences, training, social networks references
Banking information: Bank details
Information generated from your use of the Marketplace: emails and calls communicating with our teams, cookies and browsing data, transaction details, recommendations, messages on the integrated messaging system, information relating to Assignments.
Purpose(s) | Collection method / Source(s) | Types of data processed | Legal basis | Retention period |
---|---|---|---|---|
Verification of company legal documents Promoting easy contact by presenting Clients with Freelancers with pre-verified legal structures
Expediting payments for completed Assignments by transmitting to MangoPay, our service provider, the information they need to verify the Freelancer's legal status. | Communicated by Freelance | Personal information
Professional information
*Unless legally authorised, such as under French law obligating the principal (Client) to Due Diligence, Clients do not have access to these documents.
Banking information | Performance of the service contract & legitimate interest | Until deletion of the Account, and thereafter in compliance with legal obligations
Malt does not store records of any ID documents. These are received by Malt and immediately transmitted to MangoPay. |
Compliance with tax transparency obligations under European Directive 2021/514 | Communicated by Freelance | Personal information: (first and last name, main address, VAT number, date of birth, residential address)
Assignment information | Legal obligation | Until deletion of the Account, and thereafter in accordance with tax statutes of limitations, i.e. 10 years. |
Search engine optimisation of profiles | Communicated by Freelancer & Generated off of Marketplace usage | Personal information Professional information Assignment information | Performance of the service contract | Until account is deleted or for 5 years from the moment your Account becomes inactive |
Allowing the possibility of being contacted for Assignments in all countries where Malt is established (see list of Malt entities in article 7.5 of this Policy). | Communicated by Freelancer & Generated off of Marketplace usage | Personal information Professional information | Performance of the service contract | Until account is deleted or for 5 years from the moment your Account becomes inactive |
Presenting your profile to prospective or existing clients who need services that match your professional skills, so as to promote your profile and the Services (as defined in the CGUV), providing that your profile is not listed as unavailable.
Compiling CVs if requested by the client, as part of their internal procedures. | Communicated by Freelancer & Generated off of Marketplace usage | Personal information Professional information | Performance of the service contract | Until account is deleted or for 5 years from the moment your Account becomes inactive |
Recommending another Freelancer profile for an Assignment | Communicated by Freelance | Personal information (contact data) Professional information | Performance of the service contract | Until account is deleted or for 5 years from the moment your Account becomes inactive |
Default visibility: 100% response rate within 1 hour, to promote the profile as soon as it is created.
Adaptation of response rates and times to actual Marketplace use
Updating your availability as soon as you register and throughout your use of the Marketplace. | Generated off of Marketplace usage | Browsing data (cookies and IP address) Availability
Secure messaging usage data | Performance of service contract and consent if applicable (cookie) | Until account is deleted or for 5 years from the moment your Account becomes inactive |
Data source: Client
We process various types of personal data pertaining to you:
Personal information: last name, first name, date of birth, email address, profile photo
Company information: company logo, business sector, number of employees, invoice and contact details, bank details
Information generated by your use of the Marketplace: emails and telephone calls with our teams, cookies and browsing data, details of transactions, information relating to Assignments carried out, opinions and recommendations, data relating to the use of secure messaging (conversation content).
Purpose(s) | Collection method / Source(s) | Types of data processed | Legal basis | Retention period |
---|---|---|---|---|
Managing refunds and unpaid invoices | Communicated by the Client & generated off of Marketplace use | Professional information Assignment information | Performance of the service contract and legitimate interest | Until the account is deleted and thereafter in the event of disputes. |
Data source: Users
*As a reminder, Users refer to registered Freelancers and Clients using the Marketplace. The table below lists processing activities applicable to either.
Purpose(s) | Collection method / Source(s) | Types of data processed | Legal basis | Retention period |
---|---|---|---|---|
Generally speaking, helping to implement Malt Services | Communicated by the User and generated by use of the Marketplace | Personal information Professional information Assignment information | Performance of the service contract | Until account is deleted or for 5 years from the moment your Account becomes inactive |
Providing documents related to the Assignment: invoice, Quote, Freelancer's legal documents if necessary. | Generated off of Marketplace usage | Professional information Assignment information | Performance of the service contract and legal obligations | Until the Account is deleted + 10 years in compliance with legal statutes of limitations (accounting documents - Article L123-22 of the French Commercial Code) |
Paying Assignments directly through the Marketplace and our partner, MangoPay.
Financial flows management via the Marketplace, including invoicing for Assignments and payments. | Communicated by the User and generated by use of the Marketplace | Professional information Banking information Assignment information | Performance of the service contract and legal obligations | Until deletion of the Account + 10 years in compliance with legal statutes of limitations |
Cash advances from our various financial partners covered by the T&Cs (factoring and loan contracts) | Communicated by the User and generated by use of the Marketplace | Personal information Professional information Assignment information | Performance of the service contract and legal obligations | Until account deletion +5 years, in the event a loan was taken out, as defined by Defacto |
Leaving a review / comment at the end of the Assignment | Communicated by the User | Assignment information | Performance of the service contract | Until your account is deleted or for 5 years from the moment your Account becomes inactive. As a result, we retain only the review and delete any data identifying its author. |
Sending relevant communications and notifications tailored by Marketplace usage | Communicated by the User and generated by use of the Marketplace | Personal information Navigation data Assignment information | Legitimate interest | Until your account is deleted, for 5 years from the time your account becomes inactive, or until User exercises right to object. Objecting does not affect the legality of how data was collected and used previously. |
Communications on Malt news and events | Communicated by the User | Personal information | Legitimate interest | Until your account is deleted, for 5 years from the time your account becomes inactive, or until User exercises right to object. Objecting does not affect the legality of how data was collected and used previously. |
Securing the site and its various domains | Generated off of Marketplace usage | Navigation data Assignment information | Legitimate interest and consent where applicable (cookie) | Until your account is deleted, for 5 years from the time your account becomes inactive, or until User exercises right to object. Objecting does not affect the legality of how data was collected and used previously. |
Moderating to prevent fraud and spam | Generated off of Marketplace usage | Navigation data Secure messaging usage data Transaction information | Legitimate interest and consent where applicable (cookie) | Until your account is deleted, for 5 years from the time your account becomes inactive, or until User exercises right to object. Objecting does not affect the legality of how data was collected and used previously. |
Customer service assistance and mediation | Communicated by the User & Generated off of Marketplace usage | Personal and professional information Secure messaging usage data Transaction information | Legitimate interest | 2 years, longer is case of disputes. |
Providing secure instant messaging
Reading exchanged messages if necessary to prevent fraud and assist Users | Generated off of Marketplace usage | Secure messaging usage data | Legitimate interest | Until your account is deleted, for 5 years from the time your account becomes inactive, or until User exercises right to object. Objecting does not affect the legality of how data was collected and used previously. |
Updating Services and features
Producing statistics on Service usage, as well as Monitoring website page audiences, sales activities and User behavior on the Marketplace. | Generated off of Marketplace usage | Personal information Professional information Navigation data - anonymizing wherever possible | Legitimate interest and consent | Until your account is deleted, for 5 years from the time your account becomes inactive, or until User exercises right to object. Objecting does not affect the legality of how data was collected and used previously. |
Offering to take part in test panels, satisfaction surveys, or surveys on the world of freelancing | Communicated by the User | Personal information | Legitimate interest and consent where applicable | For the duration of the study or until User exercises right to object |
Recording videoconference calls with our sales team | Communicated by the User | Personal information Professional information | Legitimate interest | 1 year |
Using profile photos or photos taken during events for internal and external commercial purposes | Communicated by the User | Personal information | Consent | 5 years or until consent is withdrawn. Withdrawal of consent does not affect the legality of how data was collected and used previously. |
Recording of Malt Academy webinars to make them available as replays on our professional YouTube account. | Communicated by the User | Personal information | Consent | 5 years or until User exercises right to object. Objecting does not affect the legality of how data was collected and used previously. |
Responding to your request to exercise your rights | Communicated by the User & Generated off of Marketplace usage | All information processed by Malt pertaining to the request submitted | Legal obligation (GDPR) | Until account deletion |
Data source: Prospects and site visitors
Purpose(s) | Collection method / Source(s) | Types of data processed | Legal basis | Retention period |
---|---|---|---|---|
Communications on Malt news and events | Communicated by the prospect or site visitor | Prospects | Consent | Until consent is withdrawn. Withdrawal of consent does not affect the legality of how data was collected and used previously. |
2. How AI is used at Malt
Malt's algorithm, based on an artificial intelligence (AI) system, analyses information collected from Users and generated by their use of the Marketplace, as described above, in order to present Freelancer profiles to Clients, Assignments to Freelancers, and improve their visibility.
We may also use artificial intelligence systems to ensure the security of the Marketplace (e.g. robot detection, fraud and spam prevention).
To find out more, please consult the following articles:
How the Malt algorithm works: https://www.malt.uk/resources/article/how-does-malts-algorithm-work
Transparent procedures for referencing and moderating at Malt: https://en.malt.fr/c/transparency
3. Our cookies policy
We use authentication cookies, security cookies and cookies relating to site integrity, location cookies, cookies relating to site functionality and services, analysis and research cookies and cookies for advertising purposes.
You can accept, refuse or set your cookie preferences when you first log on to the Marketplace, and change your preferences at any time by consulting the cookies section of our data protection center, available here: https://en.malt.fr/about/privacy/cookies. You will also find a more detailed description of the cookies we set.
4. Recipients and transmission of data
We are the recipient of the personal data collected via the Marketplace and use it only for the purposes explained above. Under no circumstances do we sell this information to third parties.
4.1 Sharing between Users
We may share information relating to Users in order to facilitate their interaction, to provide them with business opportunities that may correspond to the Freelancer's professional skills and the business needs of Clients, and to enable the contracting of Assignments.
Some Clients may be based outside the European Union; some are based in countries subject to an adequacy decision by the European Commission; for other countries, measures have been taken with Clients in accordance with applicable data protection legislation to guarantee the transfer of data, such as the standard contractual clauses adopted by the European Commission.
4.2 Between Malt entities
Malt is made up of Malt Community (parent company) and its subsidiaries, namely the following companies: Malt Community SL (Spain), Malt Community GmbH (Germany), Malt Community BV (Netherlands), Malt Community Belgium (Belgium), Malt Community Ltd (United Kingdom), Malt Software Design LLC (United Arab Emirates). We share data within the Malt group.
Following the acquisition of Comatch GmbH in 2022, Malt and Comatch joined their respective databases, which included profile data provided by Freelancers and Client representatives.
We may feature Freelancer profiles, or recommend a Client Assignment, regardless of whether or not they are established in the various countries where Malt is incorporated.
4.3 With our investors, accountants and auditors
We may share information relating to Users in order to respond to requests for information from our investors, accountants and auditors, particularly in the context of any fundraising or verification of the use of funds raised, in compliance with the regulations in force.
4.4 With authorised third parties
We may disclose your information if this is reasonably necessary to satisfy a legal or regulatory obligation, a legal proceeding or administrative request, to protect the safety of any person, to deal with any problem of a fraudulent, security or technical nature, or to protect the rights of Users.
4.5 With trusted service providers
Data location information : All our servers on which your data is stored are located in Europe.
On a highly exceptional basis, some of our service providers, whose principal place of business is in a country outside the European Union, may need to transfer your data to that country. In this case, we check beforehand that they comply with their obligations in terms of personal data protection, and put in place a "transfer tool", such as standard contractual clauses, to guarantee protection of your personal data equivalent to that offered within the European Union.
You will find below a list of Malt's service providers, the purpose for which they operate, their location and the appropriate safeguards adopted where applicable.
Name of the Service provider | Purpose(s) | Persons concerned | Data localisation |
---|---|---|---|
MangoPay SA | Mangopay opens a payment account on your behalf, enabling you to receive or execute a payment for the assignments carried out via our service. MangoPay also verifies that cash flow via the Marketplace does not originate from money laundering and is not used to fund terrorism. | Freelancers and Customers | Luxembourg (EU) |
Defacto SAS | Company specialising in no-cost cash advancs of Freelancer invoices issued via the Marketplace through the provision of participatory loans for which Malt stands surety | Freelancers and Customers | France (EU) |
Billie GmbH | Company specialising in the repurchase of invoices from freelancers issued via the Marketplace | Freelancers and Customers | Germany (EU) |
Aria | Factoring service | Freelancers and Customers | France (EU) |
Stripe | Direct debit | Customers | Irland (EU) |
Upflow | Invoices reminder to Customers | Customers | France (EU) |
Studycall | Lead management and reactivation | Customers | Irland (EU) |
Mailchimp https://mailchimp.com/about/security/#Investing_in_Your_Privacy | Sending emails to site users and anyone invited by a user to use Malt or write a recommendation concerning Malt. | Freelancers, customers and customers prospects | Data Transfers to the United States - standard contractual clauses and implementation of additional safeguards. |
MongoDB | Back-ups of the database | Freelancers and Customers | Belgium (EU) Certified Data Privacy Framework |
Google Cloud Platform | Hosting of data processed by Malt | Freelancers and Customers | Belgium (EU). In the case of data transfers to the United States - standard contractual clauses and implementation of additional safeguards |
Google Suite | Drive management and electronic messaging | United States - standard contractual clauses and additional guarantees. | Data Transfers to the United States - standard contractual clauses and implementation of additional safeguards. |
Datadog | Management of connection logs to secure the Marketplace. | Freelancers and Customers | Data Transfers to the United States - standard contractual clauses and implementation of additional safeguards - certified Data Privacy Framework |
Vadata | Securing the Marketplace by performing penetration tests. | Freelancers and Customers | France (EU) |
Aircall | Management of the relationship with the users and telephone exchanges. | Freelancers and Customers | Data Transfers to the United States - standard contractual clauses and implementation of additional safeguards - certified Data Privacy Framework |
Calendly | Managing meetings with Freelancers and Customers | Freelancers and Customers | Data Transfers to the United States - standard contractual clauses and implementation of additional safeguards. |
Front App | Support to users that have contacted the Customer Experience team | Freelancers and Customers | Data Transfers to the United States - standard contractual clauses and implementation of additional safeguards - certified Data Privacy Framework |
Looker | Data analysis | Freelancers and Customers | The Netherlands - Certified Data Privacy Framework |
Chartio Inc, et Google LLC (Google analytics) | Statistical analysis | Freelancers and Customers | Data Transfers to the United States - standard contractual clauses and implementation of additional safeguards. |
Onetrust | Consent tool for cookies | Freelancers, Customers and customers prospects | Data Transfers to the United States - standard contractual clauses and implementation of additional safeguards. |
Salesforce | CRM and Management tool of contracts | Freelancers and Customers | Data Transfers to the United States - standard contractual clauses and implementation of additional safeguards. |
Typeform | Online surveys | Freelancers, Customers and customers prospects | Spain (EU) |
Trustpilot | Collection of Marketplace users' opinions | Freelancers and Customers | Data Transfers to the United States - standard contractual clauses and implementation of additional safeguards. |
Ashtone | Debt collection tool | Freelancers and Customers | France (EU) |
Hubspot | Marketing emails | Freelancers, Customers and customers prospects | Data Transfers to the United States - standard contractual clauses and implementation of additional safeguards - certified Data Privacy Framework |
Salesloft | Marketing emails | Freelancers, Customers and customers prospects | Data Transfers to the United States - standard contractual clauses and implementation of additional safeguards. |
Crispchat | Online chat | Freelancers, Customers and customers prospects | Data Transfers to the United States - standard contractual clauses and implementation of additional safeguards. |
Modjo | Conversational analysis tool | Customers and customers prospects | France (EU) |
5. Data security
We consider the security and confidentiality of our Users' data to be of the utmost importance.
We implement appropriate technical and organizational measures to guarantee the security, confidentiality, integrity, availability and resilience of our information system and of your data, in order to protect the data we process from destruction, loss, alteration, disclosure or unauthorized access.
In particular:
We encrypt most of our Services using SSL technology.
We verify your email address when you create your Account.
We conduct internal audits of data collection, storage, and processing, including physical security measures, to prevent unauthorized access to our systems.
We restrict personal data access only to Malt employees and service providers who require access in order to process it on our behalf, in keeping with the GDPR data minimisation principle. They are held to an obligation of strict confidentiality, and may be subject to disciplinary sanctions up to and including dismissal in the event of breach.
6. Your rights
You can find descriptions of each of your rights, and how to exercise them, in the "Your rights" section of this Data Protection Center.
In accordance with data protection regulations, you have the following rights:
6.1 The right of access - GDPR Article 15
You have the right to access your personal data processed by Malt. It allows you to find out what data we hold on you and, if you wish, to request a copy, within the limits of respect for the rights of third parties whose personal data may be included in the data concerning you.
6.2 The right to rectification - GDPR Article 16
You may request Malt to rectify any personal data concerning you that is inaccurate, out of date, or incomplete. This request must be justified.
To make it as easy as possible for you to exercise this right, you may make these changes and additions directly in your Account settings.
If you feel that other information about you needs to be changed or supplemented and you are unable to make the change yourself, you may request modifications by writing to us at [email protected].
6.3 The right to erasure - GDPR Article 17
You have the right to obtain from us the deletion of personal data concerning you, without undue delay, provided that its retention is not in our legitimate interest or required by any legal obligation.
For security reasons and to avoid unwanted deletion of the account, you may perform this step yourself by logging into your account and following this link: www.malt.uk/account/cancellation
Once you have agreed to be listed, search engines and other third parties may still retain copies of your public profile information for some time, even after you have deleted the information from the Malt site or deactivated your account. Malt is not liable for such processing of your data by third parties.
6.4 The right to limitation - GDPR Article 18
You may request Malt to restrict the processing of your data (for example, making your profile temporarily unavailable on the site), where any of the following apply:
You dispute the accuracy of your personal data. In this case, we will hide your data for a period of time that will allow us to verify its accuracy.
You consider that the processing of your data is carried out unlawfully and you object to their deletion and request instead restricting their use.
Your personal data is no longer required for processing purposes, but is still necessary to enable you to assert, exercise or defend a legal claim.
You have exercised your right to object. We will restrict the processing of your data while we check whether the legitimate reasons we are pursuing override your right.
If we decide to lift the restriction on the processing of your personal data, we will inform you accordingly.
6.5 The right to object - GDPR Article 21
You may object to the use of your information if the following two conditions are met: (i) you provide justification relating to your specific situation, and (ii) the legal basis for our use is the pursuit of a legitimate interest.
Malt will then discontinue the processing unless there are compelling legitimate grounds for continuing the processing, or for establishing, exercising or defending legal claims.
For example, you may object to Malt sending you communications, particularly of a commercial nature. To this end, we provide you with an unsubscribe link in all emails sent to you. You can manage notification settings directly in our Data Protection Center under tab, Your Rights https://en.malt.fr/about/privacy/rights.
6.6 The right to portability - GDPR Article 20
You can request the portability of your data at any time. In exercising this right, we undertake to transmit to you, within a reasonable time and in a machine-readable format, any data you have provided to us, whether declared by yourself or generated by your activity on the Marketplace.
6.7 The right to withdraw consent - GDPR Article 7
Insofar as the processing of your personal data is based on your consent, you have the right to withdraw your consent at any time. However, this does not affect the validity of your consent in the past.
6.8 The right to organise what happens to your data in the event of your death - Article 85 Data Protection Act
You can give us instructions on how to store, delete and communicate information about you after your death.
6.9 The right to lodge a complaint with a supervisory authority
In the event of a dispute that cannot be resolved amicably, you are always entitled to contact the relevant General Data Protection Regulation authority to lodge a complaint.
The supervisory authority competent to deal with any request concerning us, including, where applicable, a complaint from a User, is the Commission Nationale de l'Informatique et des Libertés (CNIL).
Website: https://www.cnil.fr/en
You can always contact any data protection authority, particularly in your country of residence, the country where you work, or the country of which you are a citizen, who will forward your request to the CNIL.
Directory of authorities within the EU: https://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm