Privacy Policy

Effective Date: July 2026

Version: 1.0

1. Introduction

Paris Business Academy, a company registered in France, with its registered office at 7 allée Sainte-Lucie, 92130 Issy-les-Moulineaux, France (“Paris Business Academy”, “PBA”, “we”, “us” or “our”), respects your privacy and is committed to protecting your personal data.

We operate the online learning portal available at:
https://www.e-pba.fr

Through the Portal, we provide online courses, learning materials, assessments, examinations, mentoring, student-support services and other related educational services.

This Privacy Policy explains:

  1. what personal data we collect;
  2. how we collect it;
  3. why we process it;
  4. the legal bases on which we rely;
  5. how we use camera-based student verification;
  6. who may receive your personal data;
  7. whether we transfer data outside the European Economic Area;
  8. how long we retain personal data;
  9. how we protect personal data; and
  10. the rights available to you.

This Privacy Policy applies when PBA acts as the data controller for personal data processed through the Portal and in connection with our Online Courses.

You should read this Privacy Policy together with our Terms and Conditions, Cookie Policy, Course Outline and any additional privacy notice displayed when a particular feature is activated.

2. Data Controller

The data controller responsible for your personal data is:

Paris Business Academy
Registered office: 7 allée Sainte-Lucie, 92130 Issy-les-Moulineaux, France
Email: info@paris-business-academy.com

Where PBA has appointed a Data Protection Officer, their contact details are:

Email: info@paris-business-academy.com
Postal address:7 allée Sainte-Lucie, 92130 Issy-les-Moulineaux, France

3. Scope of This Privacy Policy

This Privacy Policy applies to personal data processed in connection with:

  1. visiting and using the Portal;
  2. creating and managing an account;
  3. applying for or enrolling in an Online Course;
  4. making payments;
  5. accessing Course Materials;
  6. viewing course videos;
  7. completing assignments, quizzes and examinations;
  8. participating in mentoring and discussion areas;
  9. camera-based identity and engagement verification;
  10. contacting our academic, technical or administrative teams;
  11. receiving marketing communications;
  12. submitting complaints or exercising legal rights; and
  13. obtaining certificates or academic records.

This Privacy Policy does not directly govern independent websites or services operated by third parties. Those providers may issue their own privacy notices.

4. Important Definitions

For the purposes of this Privacy Policy:

  1. “Personal data” means information relating to an identified or identifiable natural person.
  2. “Processing” means any operation performed on personal data, including collecting, recording, organising, storing, using, consulting, sharing, modifying, restricting, deleting or destroying it.
  3. “Data subject” means the person to whom personal data relates.
  4. “Portal” means the online learning platform available at https://www.e-pba.fr.
  5. “Online Course” means any online educational course or programme offered through the Portal.
  6. “Course Materials” include recorded lectures, videos, podcasts, readings, presentations, quizzes, assignments, examinations and other educational resources.
  7. “Camera Snapshots” means still images periodically captured through a student’s device camera while the student accesses designated course videos or monitored activities.
  8. “Special-category data” includes information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used to uniquely identify a person, health information, and information concerning a person’s sex life or sexual orientation.

5. Personal Data We Collect

We may collect the categories of personal data described below.

5.1 Account and profile information

This may include:

  1. title;
  2. full name;
  3. date of birth;
  4. email address;
  5. telephone number;
  6. postal address;
  7. nationality;
  8. country of residence;
  9. username;
  10. password in encrypted or hashed form;
  11. profile photograph;
  12. preferred language;
  13. account preferences; and
  14. parent or legal guardian information where applicable.

We normally receive this information directly from you when you create or manage an account.

5.2 Identity and eligibility information

This may include:

  1. passport;
  2. national identity card;
  3. driving licence;
  4. date and place of birth;
  5. photograph;
  6. signature;
  7. academic certificates;
  8. transcripts;
  9. proof of English-language proficiency;
  10. employment or professional-experience information;
  11. proof of address;
  12. visa or immigration-related information where relevant; and
  13. supporting enrolment documents.

We collect this information directly from you or, where authorised, from an education agent, employer, sponsor, parent or legal guardian.

5.3 Learning and academic information

This may include:

  1. courses and modules in which you enrol;
  2. video-viewing activity;
  3. course progress;
  4. time spent accessing Course Materials;
  5. completion records;
  6. quiz and examination answers;
  7. examination scores;
  8. assignments and projects;
  9. plagiarism reports;
  10. assessment feedback;
  11. academic-integrity records;
  12. tutor and E-Mentor communications;
  13. attendance and participation records;
  14. reassessment information;
  15. certificates awarded; and
  16. learning-support requests.

We collect this information from your activities on the Portal and from lecturers, E-Mentors, assessors and authorised service providers.

5.4 Camera and engagement-verification information

When camera verification applies to a designated course video or learning activity, we may collect:

  1. still images captured through your device camera approximately once every five minutes;
  2. the date and time of each snapshot;
  3. the course, module or video being accessed;
  4. account and session identifiers;
  5. whether a face or person appeared to be present;
  6. camera permission status;
  7. verification interruptions or failures;
  8. manual-review results;
  9. suspected manipulation or circumvention records; and
  10. related technical logs.

Unless we clearly inform you otherwise, we do not continuously record video or audio during ordinary course-video monitoring.

We will provide an on-screen notice before activating the camera and will request the technical permission needed to access your device camera.

5.5 Examination and proctoring information

Where an Online Course includes a remotely monitored examination, we may collect:

  1. webcam images or video;
  2. microphone or audio information;
  3. screen activity;
  4. browser activity;
  5. identity-document images;
  6. room or environment checks;
  7. examination start and finish times;
  8. keyboard, mouse or device events;
  9. IP address and device information;
  10. proctoring alerts;
  11. recordings of suspected incidents; and
  12. human-review decisions.

The precise monitoring method will be disclosed before the examination.

5.6 Communications and interaction information

This may include:

  1. emails;
  2. telephone communications;
  3. live-chat messages;
  4. support requests;
  5. complaints;
  6. enquiries;
  7. meeting records;
  8. survey responses;
  9. communications with E-Mentors and lecturers; and
  10. records of your preferences and instructions.

5.7 Shared and user-generated content

This may include:

  1. discussion-board posts;
  2. questions and answers;
  3. reviews;
  4. comments;
  5. messages to other students;
  6. photographs;
  7. uploaded documents;
  8. course submissions; and
  9. other materials that you choose to share.

Some Shared Content may be visible to other students or Portal users. The Portal will indicate when content is visible to others.

5.8 Financial and transaction information

This may include:

  1. course fees;
  2. payment status;
  3. transaction references;
  4. invoices;
  5. receipts;
  6. instalment plans;
  7. refunds;
  8. sponsor or payer details;
  9. bank information where required for a refund; and
  10. limited payment-card information.

Payment-card details may be processed directly by an authorised payment provider. We may not receive or store the complete card number or card-security code.

5.9 Technical and usage information

We may automatically collect:

  1. IP address;
  2. browser type and version;
  3. operating system;
  4. device type;
  5. device identifiers;
  6. screen size;
  7. language and time-zone settings;
  8. login dates and times;
  9. pages and Course Materials accessed;
  10. frequency and duration of visits;
  11. session activity;
  12. error reports;
  13. security events;
  14. approximate location derived from an IP address;
  15. cookie identifiers; and
  16. referring website information.

We use this information to operate, secure, maintain and improve the Portal.

5.10 Marketing information

This may include:

  1. your marketing preferences;
  2. communication-channel preferences;
  3. consent records;
  4. courses that may interest you;
  5. responses to campaigns; and
  6. records of whether you opened or interacted with a communication.

6. How We Collect Personal Data

We collect personal data:

  1. directly from you;
  2. through your activities on the Portal;
  3. from lecturers, E-Mentors, assessors and administrative staff;
  4. from education agents or recruitment partners authorised by you;
  5. from parents, guardians, employers or sponsors where relevant;
  6. from payment providers;
  7. from examination and anti-plagiarism providers;
  8. from camera-verification and proctoring providers;
  9. from cookies and similar technologies;
  10. from publicly available sources where lawful; and
  11. from regulatory or governmental bodies where necessary.

Where another person provides personal data about you, we require that person to have an appropriate authority or lawful basis to do so.

7. Purposes and Legal Bases for Processing

We process personal data only where we have a valid legal basis.

7.1 Creating and managing your account

Purpose: To register you, create your student account, authenticate logins, maintain your profile and provide Portal access.

Data used: Account information, profile information, contact information and technical information.

Legal basis: Performance of a contract or steps taken at your request before entering into a contract.

7.2 Processing applications and enrolments

Purpose: To assess eligibility, verify identity, review supporting documents and confirm enrolment.

Data used: Profile, identity, qualification, language-proficiency and communication information.

Legal basis: Performance of a contract or pre-contractual steps; compliance with legal obligations where applicable; and our legitimate interest in preventing fraud and protecting academic standards.

7.3 Delivering Online Courses

Purpose: To provide Course Materials, academic support, mentoring, assessments, feedback, progress tracking and certification.

Data used: Profile, learning, interaction, technical and usage information.

Legal basis: Performance of the contract between you and PBA.

7.4 Monitoring course engagement and identity

Purpose: To confirm that the registered student is accessing and engaging with designated Course Materials, prevent account sharing and impersonation, validate participation records and protect the credibility of course completion and certificates.

Data used: Camera Snapshots, session information, course progress, device information, account identifiers and verification results.

Legal basis: Our legitimate interests in:

  1. protecting the integrity of our educational services;
  2. preventing account sharing, impersonation and fraud;
  3. confirming genuine student participation;
  4. protecting the value of certificates; and
  5. enforcing our Terms and Conditions.

Where the circumstances require another lawful basis, including consent, we will obtain it before processing begins.

We will balance our interests against your rights and freedoms and apply measures designed to reduce unnecessary intrusion.

Technical permission granted through your browser or device allows the camera to operate. It does not necessarily mean that consent is the GDPR legal basis for all processing associated with the monitoring system.

7.5 Administering assessments and examinations

Purpose: To conduct, mark and review assessments; verify identity; prevent cheating; investigate irregularities; and manage reassessment.

Data used: Identity, learning, examination, technical, proctoring and communication information.

Legal basis: Performance of the contract; our legitimate interest in maintaining academic integrity; and compliance with applicable legal or accreditation obligations.

7.6 Managing payments

Purpose: To process fees, instalments, invoices, receipts and refunds and recover outstanding amounts.

Data used: Profile, financial, transaction and communication information.

Legal basis: Performance of a contract; compliance with accounting and tax obligations; and our legitimate interest in recovering amounts lawfully owed.

7.7 Providing discussion boards and interactive features

Purpose: To permit communication between students, lecturers and E-Mentors and support collaborative learning.

Data used: Profile information, Shared Content, communications and usage information.

Legal basis: Performance of the contract and our legitimate interest in providing an effective learning environment.

Where publication of particular optional content depends on your consent, you may withdraw that consent, subject to any other lawful basis that applies.

7.8 Providing customer, academic and technical support

Purpose: To respond to questions, resolve technical issues, provide academic guidance and manage complaints.

Data used: Profile, communications, learning, technical and usage information.

Legal basis: Performance of a contract and our legitimate interest in supporting students and operating the Portal effectively.

7.9 Maintaining security and preventing misuse

Purpose: To detect, prevent and investigate unauthorised access, fraud, account sharing, malware, attacks, intellectual-property infringement and other violations.

Data used: Account, identity, camera, usage, device, security and communications information.

Legal basis: Our legitimate interests in protecting students, PBA, the Portal and our intellectual property; compliance with legal obligations; and the establishment, exercise or defence of legal claims.

7.10 Complying with legal and regulatory obligations

Purpose: To meet tax, accounting, consumer, data-protection, court, regulatory, education and law-enforcement requirements.

Data used: Any categories reasonably required for the relevant obligation.

Legal basis: Compliance with a legal obligation and, where applicable, the establishment, exercise or defence of legal claims.

7.11 Improving courses and the Portal

Purpose: To analyse course performance, improve student experience, correct technical issues and develop our educational services.

Data used: Learning, usage, technical, communication and survey information.

Legal basis: Our legitimate interests in improving the Portal and Online Courses.

Where reasonably possible, we use aggregated or anonymised information for analytics.

7.12 Marketing

Purpose: To send information about courses, events, offers and related services.

Data used: Name, email address, telephone number, preferences, interests and previous interactions.

Legal basis: Consent where required by law or our legitimate interests where direct marketing is legally permitted.

You may opt out of marketing communications at any time by using the unsubscribe link or contacting us.

Opting out of marketing will not prevent us from sending necessary administrative, academic, contractual or security communications.

7.13 Corporate transactions

Purpose: To support a proposed merger, acquisition, investment, restructuring, financing, sale or transfer of all or part of the business.

Data used: Relevant personal data, limited as far as reasonably possible.

Legal basis: Our legitimate interest in managing and developing our organisation.

We will use confidentiality arrangements and, where possible, share anonymised or limited information during preliminary stages.

8. Camera-Based Student Verification

8.1 How the monitoring works

For designated course videos, the Portal may request access to your device camera and capture a still image approximately once every five minutes while the video is actively playing.

The monitoring system is used to help verify that:

  1. the registered student is present;
  2. the account is not being shared;
  3. another person is not completing course activities on the student’s behalf;
  4. the student is genuinely engaging with required learning content; and
  5. recorded participation is reliable.

A visible notice will be displayed before camera access begins.

8.2 What the system does not ordinarily collect

Unless a separate notice states otherwise, ordinary course-video verification:

  1. does not continuously record video;
  2. does not record audio;
  3. does not remain active after you leave the designated learning activity;
  4. does not use the camera when the relevant video is not playing;
  5. does not use images for advertising;
  6. does not sell Camera Snapshots;
  7. does not publish Camera Snapshots; and
  8. does not perform facial recognition or emotion recognition.

8.3 Human review

An unclear, missing or unsuccessful Camera Snapshot does not automatically establish misconduct.

Where the system identifies an irregularity, authorised personnel may review relevant snapshots, session records and technical information.

We will consider:

  1. technical failures;
  2. lighting or camera-quality problems;
  3. internet interruptions;
  4. accessibility needs;
  5. accidental appearances by another person; and
  6. any explanation provided by the student.

A decision to suspend access, invalidate participation, withhold a certificate or take disciplinary action will not be based solely on an unclear image or automated alert without appropriate human review.

8.4 Environment and third parties

You should access monitored videos in an appropriate private environment.

You should take reasonable steps to ensure that:

  1. no other person appears unnecessarily in the camera view;
  2. confidential documents are not visible;
  3. sensitive information is not displayed in the background; and
  4. you do not activate monitoring in a location where recording would be inappropriate or unlawful.

Where another person appears incidentally, we will limit the use and retention of that image as far as reasonably possible.

8.5 Failure to provide camera access

Where camera verification is a clearly disclosed requirement for a designated course activity, refusing or disabling camera access may mean that:

  1. the video cannot start or continue;
  2. the activity will not be recorded as completed;
  3. additional identity verification will be required; or
  4. another suitable verification method must be arranged.

We will explain the consequences before the monitoring begins.

8.6 Alternative arrangements

Students who cannot use camera monitoring because of:

  1. disability;
  2. accessibility requirements;
  3. lack of compatible equipment;
  4. personal safety concerns;
  5. religious or cultural considerations;
  6. exceptional household circumstances; or
  7. another legitimate reason

may contact us at info@paris-business-academy.com.

Where reasonably possible and consistent with course integrity, we will consider an alternative method such as:

  1. manual identity verification;
  2. scheduled video verification;
  3. periodic on-screen confirmations;
  4. document-based verification;
  5. supervised engagement; or
  6. another proportionate arrangement.

8.7 Facial recognition and biometric processing

Camera Snapshots contain images of a person and therefore constitute personal data.

We do not intend to create facial templates or use Camera Snapshots for automated facial recognition, biometric matching or unique biometric identification.

A photograph does not automatically constitute special-category biometric data. However, it may become biometric data where specific technical processing is applied to physical or behavioural characteristics for the purpose of uniquely identifying a person.

We will not introduce facial recognition or biometric identification without:

  1. completing an appropriate legal assessment;
  2. identifying an Article 6 GDPR legal basis;
  3. identifying an applicable Article 9 GDPR condition;
  4. completing any required Data Protection Impact Assessment;
  5. implementing additional safeguards;
  6. providing a separate and clear notice; and
  7. obtaining explicit consent where consent is the required legal basis.

9. Special-Category Personal Data

We do not intentionally request special-category personal data as part of ordinary enrolment, except where it is necessary and lawful.

We may process limited special-category data where:

  1. you request disability or accessibility support;
  2. health information is required to make reasonable arrangements;
  3. you voluntarily disclose such information in communications or assignments;
  4. it is necessary to protect vital interests;
  5. it is necessary to establish, exercise or defend legal claims; or
  6. you provide explicit consent for a clearly stated purpose.

We will restrict access to such information and apply additional safeguards.

You should avoid including unnecessary special-category information in assignments, discussions, messages or camera backgrounds.

10. Criminal-Offence Information

We do not ordinarily collect information concerning criminal convictions or offences.

We may process such information where:

  1. required by law;
  2. necessary for safeguarding;
  3. relevant to fraud or cybersecurity investigations;
  4. provided during legal proceedings; or
  5. processed under the control of an appropriate official authority or another lawful condition.

11. Children and Students Under 18

Our Services are primarily intended for adults.

Where a student under 18 is permitted to enrol, we may require:

  1. parent or legal guardian details;
  2. proof of parental responsibility;
  3. parental authorisation;
  4. consent where legally required; and
  5. additional safeguards concerning monitoring and communications.

We will provide appropriate information to the minor and the parent or guardian in clear language.

Where camera monitoring applies to a minor, we will assess the necessity and proportionality of the monitoring and obtain any legally required authorisation before activation.

12. Automated Decision-Making

12.1 Automated quiz marking

Some multiple-choice quizzes or examinations may be marked automatically.

Automated marking may calculate a score by comparing the answers submitted with predetermined correct answers.

Where automated marking produces legal or similarly significant effects, we will ensure that an appropriate legal basis applies and that you can:

  1. request human intervention;
  2. express your point of view;
  3. challenge the result; and
  4. request a manual review where appropriate.

12.2 Plagiarism-detection tools

We may use plagiarism-detection services, including Turnitin or a similar provider.

A plagiarism score or automated alert will not ordinarily determine the outcome by itself. An authorised person will review the relevant submission and surrounding circumstances before making a finding of academic misconduct.

12.3 Camera-monitoring alerts

Camera-monitoring systems may generate alerts relating to:

  1. absence from the camera view;
  2. repeated verification failures;
  3. potential account sharing;
  4. unusual session behaviour; or
  5. attempted circumvention.

These alerts support human review and will not ordinarily constitute a final decision by themselves.

13. When Providing Personal Data Is Mandatory

Certain information is necessary for us to enter into and perform a contract with you.

For example, we cannot ordinarily:

  1. create an account without basic profile and contact information;
  2. verify eligibility without required supporting documents;
  3. process payment without transaction information;
  4. assess your work without assignments or examination answers;
  5. issue a certificate without maintaining academic records; or
  6. verify participation in a monitored activity without the required verification information or an approved alternative.

Where providing personal data is mandatory, we will explain the possible consequences of not providing it.

14. Personal Data Concerning Other People

You should provide personal data relating to another person only where:

  1. it is necessary;
  2. the information is accurate;
  3. you have informed the person where required; and
  4. you have appropriate authority or another lawful basis.

You should not intentionally allow another person to appear in Camera Snapshots or examination recordings.

15. Sharing Personal Data

We may share personal data with the following recipients.

15.1 Lecturers, assessors and E-Mentors

They may receive relevant profile, learning, assessment and communication information to deliver the Online Course, provide feedback and monitor progress.

15.2 Camera-verification and proctoring providers

Where we use an external provider, it may receive:

  1. account identifiers;
  2. student name;
  3. Camera Snapshots;
  4. webcam or examination recordings;
  5. activity logs;
  6. device information;
  7. verification results; and
  8. suspected incident information.

Such providers may act as processors under our instructions or, in limited circumstances, as separate controllers. We will explain their role where required.

15.3 Plagiarism and assessment providers

They may receive assignments, student identifiers and associated information necessary to perform plagiarism checks or assessment services.

15.4 Payment providers and financial institutions

They may process transaction, payer, bank and payment-card information.

15.5 Information-technology and hosting providers

They may host, maintain, secure or support the Portal, databases, email systems, cloud services and backup systems.

15.6 Professional advisers

We may disclose personal data to lawyers, accountants, auditors, insurers, brokers and consultants where reasonably necessary.

15.7 Marketing and communications providers

Where legally permitted, service providers may help us send communications, manage contact lists and measure campaign performance.

15.8 Public and regulatory authorities

We may disclose personal data to:

  1. courts;
  2. law-enforcement authorities;
  3. tax authorities;
  4. education regulators;
  5. consumer-protection bodies;
  6. data-protection authorities; and
  7. other competent public authorities,

where required or permitted by law.

15.9 Corporate-transaction recipients

Potential purchasers, investors, lenders and their professional advisers may receive limited personal data under confidentiality obligations.

15.10 Other recipients authorised by you

We may share personal data with another person where you have clearly authorised us to do so.

16. Service Providers and Processor Obligations

Where a third party processes personal data on our behalf, we require an appropriate written agreement.

Our processors must:

  1. act only on documented instructions;
  2. apply appropriate security measures;
  3. maintain confidentiality;
  4. limit access to authorised personnel;
  5. assist us in responding to data-subject requests;
  6. notify us of relevant security incidents;
  7. delete or return data when the service ends, subject to legal requirements; and
  8. permit appropriate compliance reviews.

We do not permit processors to use personal data for unrelated purposes.

17. International Transfers

We seek to store and process personal data within France or the European Economic Area wherever reasonably possible.

However, some service providers, contractors or support personnel may be located outside the EEA.

For example, authorised technical-support services may be provided from India. This may involve remote access to limited personal data where necessary to resolve a technical issue.

Where personal data is transferred or made accessible outside the EEA, we will use a lawful transfer mechanism, such as:

  1. an adequacy decision adopted by the European Commission;
  2. the European Commission’s Standard Contractual Clauses;
  3. Binding Corporate Rules;
  4. an approved certification or code-of-conduct mechanism; or
  5. a specific GDPR derogation where legally available.

Where appropriate, we will also:

  1. conduct a transfer-impact assessment;
  2. assess the laws and practices of the destination country;
  3. restrict the information accessible to the recipient;
  4. use encryption or pseudonymisation;
  5. impose access controls;
  6. maintain contractual confidentiality;
  7. monitor the recipient’s compliance; and
  8. apply supplementary technical and organisational safeguards.

You may request information about the relevant transfer safeguard by contacting us.

18. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which we collected it, including legal, accounting, regulatory, academic, fraud-prevention and dispute-management requirements.

The retention periods below are proposed operational periods and must be confirmed before publication.

18.1 Account and profile records

Retained while the account remains active and for 2 years after closure or the end of the student relationship, unless a longer legal period applies.

18.2 Enrolment and contractual records

Retained for the duration of the contract and for 2 years afterwards to comply with legal and limitation requirements.

18.3 Financial records

Retained for the period required under French accounting and tax law, normally up to 2 years.

18.4 Academic and certification records

Core records concerning course completion, assessment results and certificates may be retained for 2 years, to verify awards, issue replacement certificates and maintain academic integrity.

18.5 Assignments and assessment materials

Retained for 2 years after marking or course completion, unless needed for an appeal, reassessment, accreditation review or dispute.

18.6 Ordinary course-video Camera Snapshots

Camera Snapshots collected approximately every five minutes during designated course videos will ordinarily be retained for 30 days after the relevant session.

They may be retained for a longer limited period where:

  1. a suspected incident is being investigated;
  2. a student disputes a participation record;
  3. disciplinary or legal proceedings are pending;
  4. retention is required by law; or
  5. the snapshots are needed to establish, exercise or defend a legal claim.

When the extended purpose ends, the snapshots will be securely deleted or irreversibly anonymised.

18.7 Examination recordings and proctoring records

Retained for 90 days after the final result or appeal period, unless an investigation or legal requirement justifies longer retention.

18.8 Technical and security logs

Retained for 90 days, depending on the security purpose and the nature of the log.

18.9 Marketing information

Retained until you withdraw consent or object to marketing, and thereafter for a limited suppression period so that we can respect your preference.

18.10 Complaints and legal disputes

Retained until the complaint or dispute is resolved and for the applicable legal limitation period.

We periodically review retained information and securely delete or anonymise data that is no longer needed.

19. Data Security

We apply technical and organisational measures designed to protect personal data against:

  1. unauthorised access;
  2. accidental loss;
  3. unlawful disclosure;
  4. alteration;
  5. destruction;
  6. misuse; and
  7. unauthorised processing.

Measures may include:

  1. encryption in transit and, where appropriate, at rest;
  2. access controls;
  3. role-based permissions;
  4. password hashing;
  5. multi-factor authentication for authorised personnel;
  6. logging and monitoring;
  7. secure backups;
  8. network and endpoint protection;
  9. staff confidentiality obligations;
  10. privacy and security training;
  11. incident-response procedures;
  12. supplier assessments;
  13. data minimisation; and
  14. scheduled deletion.

Access to Camera Snapshots and proctoring records will be limited to authorised personnel who require access for verification, academic-integrity, technical, legal or security purposes.

Although we take reasonable precautions, no online platform or transmission method can guarantee absolute security.

20. Personal Data Breaches

Where a personal data breach occurs, we will:

  1. investigate the incident;
  2. take measures to contain and remedy it;
  3. document the breach;
  4. assess the risks to affected persons;
  5. notify the CNIL where legally required; and
  6. notify affected individuals where the breach is likely to create a high risk to their rights and freedoms.

21. Your Data-Protection Rights

Subject to applicable conditions and exemptions, you may have the following rights.

21.1 Right of access

You may request confirmation of whether we process your personal data and obtain a copy of relevant information.

21.2 Right to rectification

You may request correction of inaccurate or incomplete information.

21.3 Right to erasure

You may request deletion of personal data where:

  1. it is no longer needed;
  2. you validly withdraw consent;
  3. you successfully object to processing;
  4. the processing is unlawful; or
  5. deletion is legally required.

The right to erasure is not absolute. We may retain information where necessary to comply with law, maintain academic records, defend legal claims or exercise freedom-of-expression rights.

21.4 Right to restriction

You may request restriction of processing in circumstances provided by the GDPR.

21.5 Right to data portability

Where processing is based on consent or contract and carried out by automated means, you may request eligible personal data in a structured, commonly used and machine-readable format.

21.6 Right to object

You may object, on grounds relating to your particular situation, to processing based on legitimate interests.

We will stop processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the information is required for legal claims.

You have an unconditional right to object to personal data being used for direct marketing.

21.7 Right to withdraw consent

Where processing is based on consent, you may withdraw consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

21.8 Rights concerning automated decisions

Where Article 22 GDPR applies, you may have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

You may also request human intervention, express your point of view and challenge the decision.

21.9 Right to determine instructions after death

Subject to applicable French law, you may have the right to provide instructions concerning the retention, deletion and communication of your personal data after your death.

22. Exercising Your Rights

To exercise a data-protection right, contact:

Email: info@paris-business-academy.com
Postal address: Paris Business Academy, 7 allée Sainte-Lucie, 92130 Issy-les-Moulineaux, France

Please identify the right you wish to exercise and provide enough information for us to locate the relevant records.

We may request reasonable proof of identity where necessary to prevent unauthorised disclosure.

We will normally respond within one month. We may extend the period by up to two additional months where the request is complex or numerous. We will notify you of any extension.

We will ordinarily respond without charge. We may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, as permitted by law.

23. Complaints

We encourage you to contact us first so that we can try to resolve your concern.

You also have the right to lodge a complaint with the competent data-protection authority.

In France, the supervisory authority is:

Commission Nationale de l’Informatique et des Libertés (CNIL)
Address: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
Website: www.cnil.fr

You may also complain to the supervisory authority in the European Union or European Economic Area country where you live, work or believe an infringement occurred.

24. Cookies and Similar Technologies

The Portal may use cookies and similar technologies to:

  1. maintain login sessions;
  2. remember preferences;
  3. secure the Portal;
  4. measure usage;
  5. diagnose errors;
  6. improve performance; and
  7. support marketing where permitted.

Essential cookies may be used without consent where they are strictly necessary.

We will request consent before using non-essential cookies where required by law.

Further information appears in our Cookie Policy and cookie-management tool.

25. Marketing Preferences

You may stop marketing communications by:

  1. selecting the unsubscribe link in an email;
  2. adjusting available account preferences; or
  3. contacting us.

We may retain limited information in a suppression list to ensure that we do not send further marketing messages contrary to your request.

Administrative messages concerning your account, payment, security, assessments, courses or legal notices are not marketing communications.

26. Links and Third-Party Platforms

The Portal may contain links to external websites or use embedded third-party services.

PBA does not control the privacy practices of independent third parties.

You should read the privacy policy of each external platform before providing personal data.

27. Changes to Purpose

We will normally use personal data only for the purpose for which it was collected.

Where we wish to use personal data for another purpose, we will assess whether the new purpose is compatible with the original purpose.

Where the new purpose is not compatible, we will identify another lawful basis and provide any additional information required before the new processing begins.

28. Data Protection Impact Assessment

We assess privacy risks associated with new technologies and processing activities.

Where processing is likely to create a high risk to individuals’ rights and freedoms, we will complete a Data Protection Impact Assessment before commencing that processing.

This may apply to camera-based verification, extensive proctoring, biometric technologies, systematic monitoring or new artificial-intelligence tools.

The assessment may consider:

  1. necessity;
  2. proportionality;
  3. data minimisation;
  4. possible alternatives;
  5. retention;
  6. security;
  7. risks to students;
  8. special considerations for minors or vulnerable individuals;
  9. human oversight; and
  10. measures for reducing risk.

Where a high residual risk remains, we will consult the competent supervisory authority where legally required.

29. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  1. legal or regulatory developments;
  2. changes to our Online Courses;
  3. new Portal functions;
  4. new service providers;
  5. changes to camera or proctoring systems;
  6. new security practices; or
  7. changes in our organisational structure.

We will publish the updated version on the Portal.

Where a change is material, we will provide an appropriate additional notice, such as an email, account notification or on-screen notice.

The effective date and version number will appear at the beginning of the policy.

30. Contact Us

Questions about this Privacy Policy or our handling of personal data should be sent to:

Paris Business Academy
Registered office: 7 allée Sainte-Lucie, 92130 Issy-les-Moulineaux, France
Email: info@paris-business-academy.com

Version — Version: 1.0  |  Effective Date: July 2026