MAP
Page under internal review, not published. It depends on elements that must be verified in the entity’s documents before going live. It appears neither in the site map nor on public pages.
Trust Under review

You will know who accesses which data, and for what purpose.

Your data protection officer asks three questions before approving a programme: which data are processed, who has access to them, and what becomes tamper-proof. You will find here how information is shared between roles. You will see what is recorded on the blockchain, and what is never recorded there. The documents that establish it are listed further down.

Under review Editorial status: this page is neither published, indexed nor listed in the site map.

Purposes and roles

Two distinct processing operations, not to be confused

The data collected by this site and the data processed within a programme fall under neither the same purpose nor the same allocation of roles.

ProcessingPurposeRoles
Site dataContact and demonstration requests submitted through this site.MAP is the controller for this processing.
Programme dataRunning a programme: attachment of holders, applicable rules, operations, reports.The split between controller and processor is established for each programme and written into the contract.

Categories of data

What the service processes in order to run a programme

The service processes what is necessary for issuance, for checking and for reporting, and nothing more. The exact categories depend on the programme and are set out in the contract.

Processed within the programme

  • Identification of the account holder, at the level required by the regulations.
  • Attachment of the holder to the programme and to the rules that apply to it.
  • Operations: amount, date, supplier, rule applied, reason for a refusal.
  • Exchanges necessary for support and for handling a complaint.

What is not processed

  • The contents of the basket: a supplier category does not say what was bought.
  • The personal situation reviewed by a body.
  • The data of a programme other than yours.
  • Any data that serves neither issuance, nor checking, nor reporting.

Access by role

Each role sees what concerns it, and nothing else

This is the counterpart of transparency: accounting for the use of funds does not require opening a person’s life to their funder.

Funder
Sees how its funds are used: amounts, dates, supplier categories, rules applied and reasons for refusal, within the limits of its programme. It does not see what a basket contains.
Beneficiary
Sees their own balance, their payments and the rules that apply to them. They do not see other beneficiaries’ data.
Supplier
Sees the payments it has received. It sees neither the programme budget nor the beneficiary’s situation.
Operator
Sees what is necessary for reviewing situations and administering the programme, within the limits set at the first discussion.
MAP
Accesses the data necessary for issuance, for checking operations and for reporting, according to the role of each party.

The access table for your programme is settled at the first discussion and written into the contract. Nobody holds access that does not correspond to their role.

On the chain and off the chain

Every payment in the programme is recorded on a tamper-proof blockchain. What appears there is the amount, the date, the supplier, the rule applied and the attachment to the programme. No personal data is recorded on the chain. The identity of individuals, their contact details and the documents in their file remain off-chain, in systems where they can be rectified and erased.

Retention

Retention periods are set by category and by purpose. They take into account the obligations specific to an electronic money institution, which require certain operation records to be kept. They are published here with the document that establishes them, not before.

Rights and points of contact

Data subjects exercise their rights of access, rectification, erasure, restriction and objection with the competent controller. Where MAP acts as a processor for a programme, the request is first a matter for the controller designated in the contract, and MAP assists. The exact contact is published here as soon as it is designated, and appears in the programme contract.

Documents

The documents that establish this page

A document appears here once it exists and can be provided in the mode indicated.

Record of processing activities Categories, purposes, legal bases, periods
Restricted
Table of access by role What each role sees, by programme
On request
List of processors and location of processing Role, data concerned, operating regions
On request
Standard processing agreement Commitments, instructions, security, fate of the data
Restricted
Policy of the site
The policy applicable to the data collected by this site is published separately.
What is recorded
What a record contains, and what it never contains, is described in the How it works section.