Help us design Tournée facile

Tournée facile

Privacy Policy — Tournée Facile

Last updated: 11/25/2025


1. Introduction

This Privacy Policy describes how Hakimon Solutions, a SAS with a share capital of €1000, located at 200 rue de la Croix Nivert, 75015 Paris, (hereinafter “We”) collects, uses, protects, and processes personal data when using the Tournée Facile application.

The application is intended exclusively for healthcare professionals. It involves the processing of health data, considered sensitive data under the General Data Protection Regulation (GDPR).


2. Identity of the Data Controller

Hakimon Solutions — SAS
200 rue de la Croix Nivert, 75015 Paris
SIREN: 99208019200014
GDPR / DPO Contact Email: simon@hakimon.com
Data Protection Officer: Simon DEFRETIN


3. Personal Data Collected

We only collect the data necessary for the functioning of the application.

3.1 User Account Data

  • First and last name
  • Email address
  • Phone number
  • Professional address
  • Professional identifiers (e.g., ADELI, RPPS)
  • Password (hashed and never stored in plain text)

3.2 Health Data (Sensitive Data)

  • Patient information used during rounds
  • Therapeutic notes or clinical observations
  • Medical documents or photos
  • Appointment and intervention information
  • Follow-up data (vital signs, symptoms, etc., depending on usage)

3.3 Technical Data

  • IP address
  • Technical logs
  • Application usage data
  • Cookies and trackers (see dedicated section)

3.4 Geolocation Data

  • Occasional geolocation for managing rounds
  • Route history when necessary for the app to function

3.5 Administrative Data

  • Billing data
  • Purchase or payment history

4. Purposes of Processing

The collected data is processed for:

  • Creating and managing the user account
  • Managing care rounds
  • Monitoring patient records
  • Internal messaging between professionals
  • Synchronizing data across devices
  • Hosting medical documents
  • Continuous improvement of the app (anonymized analytics)
  • Billing management and user support

5. Legal Basis for Processing

In accordance with the GDPR, processing is based on:

  • Article 6.1.b: performance of a contract (use of the application)
  • Article 6.1.c: compliance with legal obligations applicable to healthcare professionals
  • Article 9.2.h: processing of health data for healthcare and health system management purposes

6. Data Hosting and Security

6.1 Hosting

Data is hosted in France on Clever Cloud HDS-certified infrastructure, in accordance with regulations applicable to health data.

6.2 Security Measures

We implement the following measures:

  • Encryption of data in transit (HTTPS/TLS 1.2+)
  • Encryption of data at rest (AES-256 or equivalent)
  • Automatic backup systems
  • Access control and role-based access management (RBAC)
  • Access logs and security audits
  • Incident management and notification procedures

7. Subcontractors and Third Parties

We rely on the following service providers:

7.1 Audience Analytics

  • Google Analytics (with anonymization and user consent on the website only)

7.2 Hosting and Infrastructure

  • Clever Cloud (HDS) for data hosting
  • European S3-compatible storage for document storage

7.3 Messaging and Contact

  • Transactional email delivery
  • Internal contact form

8. Cookies and Trackers

On the landing page only:

  • Cookies essential for the website’s functioning
  • Analytics cookies subject to prior consent (GDPR-compliant banner)

No non-essential cookies are used in the mobile application.


9. Data Retention Period

Data is retained according to the following durations:

  • Account data: as long as the user maintains their account
  • Health data: time required for app functionality + legal obligations of healthcare professionals
  • Technical logs: up to 12 months
  • Cookies: according to durations specified in the consent banner

10. Transfer Outside the European Union

No data is transferred outside the EU.


11. User Rights

In accordance with the GDPR, you have the following rights:

  • Right of access
  • Right to rectification
  • Right to erasure (within the legal limits applicable to health data)
  • Right to restrict processing
  • Right to object
  • Right to data portability

To exercise your rights: Email: simon@hakimon.com Contact form: https://tourneefacile.com/contact


12. Application-Specific Features

The application includes:

  • Internal messaging
  • Therapeutic follow-up system
  • Appointment management
  • Data sharing between professionals
  • Multi-device synchronization
  • An API enabling certain external integrations

13. Changes to the Privacy Policy

This policy may be updated to reflect regulatory or functional changes. In the event of a significant change, users will be notified.


14. Contact

For any questions regarding this Privacy Policy: Hakimon Solutions — SAS 200 rue de la Croix Nivert, 75015 Paris
Email: simon@hakimon.com