Privacy Policy

Privacy Policy


The Cerba laboratory, whose head office is located at 10-12, avenue Rolland Moreno - ZAC DES EPINEAUX, 95740 Frépillon, France (hereinafter “Cerba”), processes your personal data as part of its medical biology activity, in compliance with current legislation.

This policy provides you with information on how your personal data is processed on MyCerba.

This policy is updated regularly to take account of changes in legislation and regulations, and any changes in the organization of the laboratory or in the processes it carries out.

This policy was updated on 07/11/2023.

What are our commitments?

We undertake to comply with the applicable regulations for all processing of personal data that we carry out. Thus, we undertake to respect the following principles:

  • We process your personal data in a lawful, fair and transparent manner.
  • We collect your personal data for specific, explicit and legitimate purposes and do not process it in a way that is incompatible with those purposes.
  • We ensure that personal data is adequate, relevant and limited to what is necessary for the purposes for which it is processed.
  • We make every effort to ensure that personal data is accurate and, where necessary, kept up to date. We take all reasonable steps to ensure that personal data which is inaccurate, having regard to the purposes for which it is processed, is deleted or rectified without delay.
  • We shall keep your personal data in a form which allows your identification only for as long as is necessary for the purposes of the processing.
  • We guarantee an appropriate level of security for the personal data we process.

These commitments are manifested in the following ways:

  • We respect your privacy.
  • We ensure that the protection and security of your personal data are our primary concern.
  • We do not use your personal data for purposes that have not been brought to your attention.
  • We do not consider that your personal data should be stored indefinitely.
  • We do not sell your personal data to third parties.
  • We work with trusted partners who provide sufficient guarantees that technical and organizational measures are in place to ensure that our processing operations meet the requirements of the applicable regulations.
  • We respect your rights as a data subject, and as a patient, and make every effort to respond to your requests as soon as they are justified.

How do we collect your personal data?

Your personal data have been entrusted to Cerba by the medical biology laboratory that performed your sampling, your healthcare establishment, or your prescribing healthcare professional who performed the sampling.

What personal data do we process and for how long?

We remind you that personal data is information relating to an identified or identifiable natural person (the "data subject"), such as your first and last names, your postal address or data concerning health.

We undertake to process only personal data that is strictly necessary for the purposes for which it is collected and to keep it only for as long as is necessary for those purposes.

The categories of personal data that we process are as follows:

Processing activities Legal basis Categories of personal data Retention period (active basis)
Laboratory management (transmission of test results, results reports and fee receipts) Execution of the contract Identification data, data concerning health and social security number 5 years from the last intervention on the medical file
Customer management (transmission of dematerialized invoices, management of equipment orders) Execution of the contract Identification data, professional data 3 years from the end of the contractual relationship
Management of the website (management of contacts, connections, account creation) Legitimate interest Identification data, connection data and logs, data relating to the management of contacts and account creation 3 years from the last contact
6 months for connection logs

Who can access your personal data?

The development and maintenance of MyCerba have been entrusted to Bluesoft; it is hosted by ATOS (a French health data hosting company).

We make every effort to ensure that the number of such persons remains as limited as possible.

We only provide our trusted service providers with the information they strictly need to provide the service, and they may not use your personal data for any other purpose.

We always make our best efforts to ensure that all our trusted service providers with whom we work maintain the security of your data.

We also ensure that, when our relationship with a trusted service provider comes to an end, they delete your personal data without delay.

We select our trusted service providers with great care, ensuring that they offer sufficient guarantees, particularly in terms of expertise, reliability, and resources, to implement technical and organizational measures capable of meeting the requirements of applicable legislation, particularly in terms of security. In this respect, we ensure that our trusted service providers process personal data only on our documented instructions. We also ensure that their staff has undertaken to respect confidentiality or is subject to an appropriate legal obligation of confidentiality.

What are your rights as a data subject?

You have the right to access, rectify, delete and port your personal data, as well as the right to limit the processing of this data.

You may exercise your rights:

  • By e-mail to the following address: rpd.cerba@lab-cerba.com
  • Or by post to the following address: 10-12, avenue Rolland Moreno – ZAC DES EPINEAUX, 95740 Frépillon, France