Privacy Policy

Last updated: July 22, 2026

1. Purpose of This Policy

This Privacy Policy describes how personal data is processed in connection with:

  • from visiting the website drifrance.eu;
  • requests for information submitted via the contact form;
  • communications via email, phone, or WhatsApp;
  • registration and participation in training sessions;
  • the administrative, contractual, and organizational management of training programs;
  • the use of the website’s statistical, technical, and security tools.

It applies exclusively to processing carried out by PhoenITx S.r.l.

Services provided directly by DRI International, WhatsApp, Google, or other external platforms are also subject to the privacy policies of their respective providers.

2. Data Controller

The website drifrance.eu and the activities presented under the name DRI France are operated by:

PhoenITx S.r.l.
Via Pietro Calvi, 2
20129 Milan
Italy

VAT number and Italian tax ID: 06466860969

Email: info@drifrance.eu
Phone: +39 02 82396499
Phone and WhatsApp in France: +33 6 83 61 59 44

PhoenITx S.r.l. acts as the data controller for the operations described in this policy.

3. Categories of Data Processed

Depending on the services used, PhoenITx S.r.l. may process the following categories of data.

Identification and Contact Information

  • first and last name;
  • email address;
  • phone number;
  • city and country;
  • company or organization to which you belong;
  • professional role, when disclosed;
  • information contained in requests and communications.

Training Data

  • selected course;
  • dates and participation guidelines;
  • the company or organization that made the registration;
  • administrative and billing information;
  • attendance and participation in the training;
  • organizational communications;
  • DRI identification code;
  • information necessary for the administration of exams or certification procedures, to the extent that such information is processed by PhoenITx S.r.l.

Technical Specifications

When you visit the website, computer systems may process, among other things:

  • IP address;
  • date and time of the connection;
  • pages viewed;
  • browser and device type;
  • operating system;
  • technical data necessary for the safety, diagnostics, and operation of the site;
  • logs related to access attempts, errors, and security events.

Data provided by WhatsApp

When a person chooses to contact PhoenITx S.r.l. via WhatsApp, the following data may be processed:

  • the phone number;
  • the name or designation associated with the account;
  • the content of the messages;
  • the date and time of the communications;
  • documents, images, or attachments that were intentionally sent.

It is recommended that you avoid sending sensitive data or confidential documents via WhatsApp unless absolutely necessary.

4. Data Source

Data is generally provided directly by the individual concerned:

  • using the form on the website;
  • by email;
  • by phone;
  • via WhatsApp;
  • at the time of registration or participation in a training session.

When a registration is submitted by a company or organization, certain information may be provided by the employer, the client, the human resources department, the training department, or an administrative contact.

In this case, PhoenITx S.r.l. processes only the information necessary for organizing and managing the training.

5. Contact Form and Requests for Information

The contact form allows you to request information about DRI France, its training programs, certifications, and services.

The data is processed for the following purposes:

  • meet the demand;
  • provide the requested information;
  • get back in touch with the person in question;
  • prepare a sales proposal;
  • organize an exchange or a meeting;
  • process a registration request.

Depending on the nature of the request, the process is as follows:

  • regarding the implementation of precontractual measures taken at the request of the data subject;
  • regarding the performance of a contract;
  • regarding PhoenITx S.r.l.’s legitimate interest in responding to requests received and managing its business relationships.

Fields marked as required are necessary to process the request. Failure to provide them may prevent PhoenITx S.r.l. from responding.

6. Registration and Participation in Training Sessions

Participant data is processed for the following purposes:

  • submit the registration;
  • check the eligibility requirements;
  • organize the training;
  • send out invitations and practical information;
  • provide access to the necessary resources or platforms;
  • manage attendance;
  • organize exams, where applicable;
  • issue documents related to participation;
  • manage billing and payments;
  • comply with administrative, accounting, and tax obligations;
  • handle any disputes that may arise.

Treatment is based primarily on:

  • the performance of the contract entered into with the participant or with the organization that purchased the training;
  • the implementation of pre-contractual measures;
  • compliance with PhoenITx S.r.l.’s legal obligations;
  • the legitimate interest in documenting the training sessions it organizes and in protecting its rights.

7. Register directly with DRI International

The official training courses offered by DRI France are part of the programs of DRI International, an organization based in the United States.

To access the services managed directly by DRI International, including:

  • to the DRI personal account;
  • the resources made available on the DRI platform;
  • on exams;
  • applications for and maintenance of certifications;
  • for services and payments managed directly by DRI International,

Participants must register personally on the official DRI International website.

During this process, the participant provides the information requested by DRI International’s platform directly to DRI International.

PhoenITx S.r.l.:

  • does not create the participant’s DRI account;
  • does not enter their personal data on the U.S. platform on their own behalf;
  • does not receive their login credentials or password;
  • does not provide DRI International with the data that the participant has already provided directly to it when creating their account.

DRI International acts independently with regard to the processing carried out on its platform. Participants must review DRI International’s privacy policy before completing their registration.

8. Six-digit DRI identification code

After registering with DRI International, the participant receives a six-digit DRI identification code.

The participant must provide this code to PhoenITx S.r.l. so that the company can verify and confirm their registration for the official training course.

As part of this procedure, PhoenITx S.r.l. provides DRI International with only the identification code. It does not simultaneously provide:

  • first and last name;
  • email address;
  • the phone number;
  • the mailing address;
  • information about the company;
  • login credentials;
  • other information entered by the participant when creating their account.

Although it does not contain any directly readable identifying information, the DRI code constitutes pseudonymized personal data, as DRI International can link it to the participant’s account.

The code is used for:

  • verify the participant’s DRI ID;
  • link the participant to the purchased training course;
  • confirm their participation;
  • carry out the tasks necessary to organize the official training.

This processing is based on the performance of the contract entered into with the participant or with the organization that purchased the training.

9. Communications by Phone and WhatsApp

The use of WhatsApp is optional. The data subject may choose to contact PhoenITx S.r.l. by email or by regular phone.

When WhatsApp is used, data is processed for the following purposes:

  • meet the demand;
  • provide information about training programs;
  • manage a registration;
  • provide practical information;
  • to pursue a pre-contractual or contractual relationship.

The legal basis is, depending on the circumstances:

  • the implementation of pre-contractual measures;
  • the performance of the contract;
  • the legitimate interest in responding to communications that have been voluntarily received.

WhatsApp is a third-party service. Using this channel means that certain information will also be processed by its provider in accordance with its own privacy policy and terms of service.

PhoenITx S.r.l. does not use the contact information received via WhatsApp to automatically send a newsletter.

10. Cookies and Similar Technologies

This site uses cookies and similar technologies.

Some cookies are strictly necessary:

  • the operation of the site;
  • safety;
  • session management;
  • storing consent-related choices;
  • protection against certain fraudulent requests, particularly through XSRF mechanisms;
  • the technical distribution of connections among the server’s resources.

These cookies do not require consent when they are essential to providing the requested service.

Non-essential statistical cookies are used only after obtaining the user’s consent.

Detailed information about cookies, their duration, and their purpose is available in the website’s Cookie Policy.

Users can accept, decline, or change their preferences at any time using the consent management feature available on the website.

11. Google Analytics

This site uses Google Analytics to collect statistical information about its use.

When consent is required, the statistical features are enabled only after the user has given their explicit consent.

In particular, the data may be used to:

  • track the number of visits;
  • understand which pages are being viewed;
  • analyze technical performance;
  • identify the most useful content;
  • improve the site’s structure and usability.

The legal basis for the processing is consent.

Consent may be withdrawn at any time, without affecting the lawfulness of the processing carried out prior to its withdrawal.

Detailed information about Google Analytics cookies is provided in the Cookie Policy.

12. Site Security and Wordfence

The site uses security tools, including Wordfence, to:

  • detect attempts at unauthorized access;
  • block malicious activities;
  • protect accounts and data;
  • analyze technical events;
  • prevent fraud and cyberattacks.

These tools can process IP addresses, technical information, server requests, and security logs.

The processing is based on PhoenITx S.r.l.’s legitimate interest in ensuring the security of the website, systems, and data.

13. Links to External Websites and Social Media Platforms

The website may contain simple links to:

  • LinkedIn;
  • X;
  • WhatsApp;
  • DRI International;
  • videoconferencing or training platforms;
  • other external websites or services.

When a user clicks one of these links, they leave drifrance.eu and access a service operated by a third party.

The third party then processes the data in accordance with its own privacy policy.

The mere presence of a link to a social media platform does not mean that PhoenITx S.r.l. receives data from the user’s social media account.

14. Recipients of the Data

To the extent necessary for the purposes described, the data may be processed by:

  • the directors, employees, and authorized representatives of PhoenITx S.r.l.;
  • instructors and staff involved in organizing the courses;
  • IT hosting and infrastructure providers;
  • email service providers;
  • maintenance and technical support providers;
  • Google and its service providers, for statistical services used with the required consent;
  • Wordfence, the provider of security services;
  • providers of telephone, messaging, and videoconferencing services;
  • banks and payment service providers;
  • accounting, tax, and legal advisors;
  • public authorities and organizations required by law to disclose such information;
  • DRI International, solely for information necessary for the administration of official programs and, in the procedure described above, primarily for the DRI identification code.

Service providers that process data on behalf of PhoenITx S.r.l. are designated as data processors in accordance with Article 28 of the GDPR, where applicable.

Personal data is not sold to third parties.

15. Data Transfers Outside the European Economic Area

Some suppliers may have offices, facilities, affiliates, or subcontractors located outside the European Economic Area.

When PhoenITx S.r.l. transfers data to a third country, the transfer must be governed in accordance with Articles 44 et seq. of the GDPR, in particular through:

  • a decision by the European Commission on adequacy;
  • standard contractual clauses approved by the European Commission;
  • other appropriate safeguards provided for by the regulations;
  • an exemption applicable to a specific situation, provided that the legal requirements are met.

Relationship with DRI International

DRI International is based in the United States.

The data that participants enter themselves when creating their accounts is provided directly by the participants to DRI International. PhoenITx S.r.l. does not collect or transfer this data on its own behalf.

PhoenITx S.r.l. provides DRI International with the DRI identification code required to verify and confirm enrollment in the official course.

This code:

  • does not contain any directly readable identity data;
  • does not contain contact information;
  • does not contain any login credentials;
  • However, DRI International may link it to the participant’s account.

PhoenITx S.r.l. thus applies the principle of data minimization by refraining from sharing with DRI International the identity and contact information that has already been provided directly by the participant.

Additional information regarding the applicable transfer mechanism may be requested from the data controller.

16. Shelf Life

Data is retained for a period of time that is proportionate to the purposes for which it was collected.

Contact Requests

Information related to requests is retained for as long as necessary to respond to them and handle any subsequent correspondence.

When the request results in a registration, an offer, or a contract, the data is included in the corresponding documentation.

Training and Contractual Relationships

Data regarding registration and participation in training courses are retained for the duration of the contractual relationship and then for as long as necessary:

  • compliance with administrative, tax, and accounting obligations;
  • claims management;
  • in defense of the rights of PhoenITx S.r.l.;
  • documentation of the training activities carried out.

Accounting and tax documents are retained for the periods specified by applicable regulations.

DRI Code

The DRI identification code is retained for as long as necessary to manage the training program and fulfill the related administrative and contractual obligations.

WhatsApp Messages

Messages are retained for as long as necessary to process the request or manage the contractual relationship.

Communications that are no longer needed may be deleted, except when further retention is necessary to comply with a legal obligation or to protect a right.

Technical and Safety Data

Technical and security logs are retained for a period of time commensurate with the need to protect the site, analyze incidents, and detect any illegal activities.

In the event of an incident, fraud, or dispute, certain data may be retained for a longer period to allow for the necessary investigations.

Statistical Data

Statistical data is retained in accordance with the configuration of the service used and the retention periods specified in the Cookie Policy.

17. Whether Data Is Required or Optional

You must provide the information marked as required on the forms in order to respond to your request or provide the requested service.

Otherwise, PhoenITx S.r.l. may not be able to:

  • respond to a request;
  • prepare a proposal;
  • submit a registration;
  • arrange participation in a training session;
  • fulfill the corresponding contractual obligations.

The other information is optional.

18. Sensitive Data

PhoenITx S.r.l. does not normally request specific categories of personal data, such as information regarding health, religious beliefs, political opinions, or sexual orientation.

Users are asked not to provide such information in open-ended fields, emails, or WhatsApp messages, except when it is strictly necessary and there is an appropriate legal basis for doing so.

19. Data Security

PhoenITx S.r.l. implements technical and organizational measures designed to protect data against:

  • unauthorized access;
  • the loss;
  • destruction;
  • deterioration;
  • improper disclosure;
  • use that is inconsistent with the stated purposes;
  • unintended unavailability;
  • cyberattacks.

Access to the data is limited to those who need it to perform their duties.

However, no computer system or means of communication can guarantee absolute security.

20. Rights of Data Subjects

Under the terms of the GDPR, the data subject may request:

  • access to their data;
  • correction of inaccurate data;
  • data erasure;
  • restriction of processing;
  • data portability, where applicable;
  • objection to processing based on a legitimate interest;
  • withdrawal of consent, where the processing is based on consent;
  • information on the safeguards applicable to international transfers;
  • the provision of data in an appropriate format, where portability applies.

Withdrawal of consent does not affect the lawfulness of the processing carried out prior to such withdrawal.

The request may be sent to:

info@drifrance.eu

PhoenITx S.r.l. may request the information reasonably necessary to verify the requester’s identity and prevent unauthorized persons from accessing the data.

21. Filing a Complaint with a Supervisory Authority

The data subject may file a complaint with the competent supervisory authority.

In particular, anyone living or working in France may contact:

National Commission for Information Technology and Civil Liberties — CNIL

The Garante per la protezione dei dati personali, the Italian authority with jurisdiction over data controllers established in Italy, may also have jurisdiction.

We recommend that you contact PhoenITx S.r.l. in advance so that we can review and, if possible, resolve your request.

22. Automated Decisions and Profiling

PhoenITx S.r.l. does not, through this website, make decisions that produce legal effects or significantly affect an individual based solely on automated processing.

The website does not use the collected data to perform automated marketing profiling specific to DRI France.

23. Policy Changes

This policy may be amended to take into account:

  • regulatory changes;
  • changes made to the site;
  • the addition or removal of services;
  • changes to the data processing procedures.

The updated version is posted on this page, along with the date of the last update.

 

This post is also available in: French