Privacy and Cookies

1. Scope and controller

The entity identified as the Publisher in the Legal Notice generally acts as controller for the data that it determines to collect and use to operate the Services. Depending on the feature, it may also act as a processor on behalf of a business customer, a joint controller, or merely a technical intermediary.

Where the Publisher’s role differs for a specific operation, including a business workspace, marketplace, payment, introduction or integration, the Service information, contract, DPA or Partner information specifies the relevant allocation of roles.

This Policy does not replace the policy of a third party that processes data for its own independent purposes, for example a seller, service provider, social network or external service where that third party acts as a separate controller.

2. Data minimisation and modularity principle

Because the Services differ, the Publisher does not necessarily collect all of the data described below for every user. Data is limited to what is relevant in light of the features used, settings, applicable obligations and reasonable security needs.

A Service may operate without an account or without certain categories of data. The inclusion of a category in this Policy describes a possibility within the overall framework and does not mean that it is systematically collected.

3. Categories of data that may be processed

Depending on the Service and use, the following categories may be processed:

4. Sensitive data and high-risk information

The user must not submit particularly sensitive data, secrets, government identifiers, detailed medical information, biometric data, confidential financial information or data concerning third parties unless the feature clearly requests it and the submission is lawful and necessary.

Where a Service legitimately requires a sensitive category, additional measures, information and legal bases may apply. A free-text field is not an invitation to communicate unnecessary sensitive information.

5. Sources of data

Data may come directly from the user, their device, their organisation, another authorised user, a Partner, a technical service provider, a lawfully accessible public source, or may be derived from interactions with the Service.

Where another person provides data concerning the user, the Publisher limits its use to the relevant legitimate purpose and provides the information required by law where applicable.

6. Main purposes

Depending on the Service, data may be used to:

7. Legal bases

Where the law requires a legal basis, processing relies, depending on the purpose, on performance of a contract or steps requested before entering into a contract, consent, compliance with a legal obligation, protection of vital interests where relevant, performance of a legally recognised task, or the legitimate interests of the Publisher or a third party where those interests are not overridden by the individual’s rights.

Legitimate interests may in particular concern security, fraud prevention, defence of rights, reasonable improvement of a Service, technical measurement or management of professional relationships. A balancing assessment is carried out where required.

Consent is requested only where that legal basis is appropriate. Withdrawal does not affect the lawfulness of prior processing and does not prevent processing based on another valid legal basis.

8. Accounts, authentication and security

Account data is used to recognise the user, manage their rights, retain their settings and detect unusual access. Security logs may be kept separately from the data visible in the profile.

Additional verification measures may be triggered in the event of an unusual login, account recovery, a sensitive change or a risk of fraud.

9. Transactions, orders and subscriptions

Where a Transaction exists, data is processed to calculate the amount, transmit the order, verify status, provide confirmation, manage performance, invoicing, support, cancellation, refunds, fraud and accounting obligations.

The identity of the seller, service provider, party collecting payment and payment service provider may vary. The information displayed during the Transaction determines the parties involved. Strictly necessary data may be exchanged among those parties to carry out the operation.

10. Payments

Payment data may be entered directly in the environment of a payment service provider. In that case, the Publisher may receive a transaction identifier, status, the last non-sensitive elements needed for support or other metadata, without receiving all of the financial information entered.

Where the Publisher itself receives or processes payment data for a specific purpose, the scope is limited to what is necessary and is subject to applicable security measures and obligations. This Policy does not claim that the same technical arrangement is used for all Transactions.

11. Introductions, leads and quotes

Where a user requests a quote, professional recommendation, contact or introduction, useful data may be communicated to one or more Partners so that they can respond. The number or category of recipients may be indicated in the user journey where relevant.

After transmission, the Partner may act as an independent controller for its own communications, quotes and contractual relationship. It must then provide its own information where required.

The Publisher must not present collection intended for an introduction as a simple internal request for information where the data will in fact be transmitted to third parties.

12. User content and public areas

Content published in a public area or shared with other users may become visible to the selected recipients and may be copied or referenced by them. The user should avoid publishing data there that they wish to keep confidential.

Content may be analysed for moderation, spam detection, security, ranking, search, translation or operation of features. Reports and moderation decisions may be retained for a reasonable period to prevent repeat misconduct and defend those decisions.

13. Artificial intelligence

Where a feature uses artificial intelligence, prompts, content, necessary context and outputs may be transmitted to a model provider or processed by specialised infrastructure. The scope depends on the Service and its configuration.

The Publisher seeks to limit data sent to what is necessary and to use appropriate contractual safeguards where the provider acts as a processor. Some providers may act for their own purposes where an integration is selected directly by the user; their policy then applies to that relationship.

This Policy does not assume that all content is used to train models. Where use of data for model training or improvement requires specific information, a choice or a particular legal basis, that must be provided appropriately.

14. Geolocation

Precise location is collected only where the feature requires it and where device permissions or the applicable legal basis allow it. The user can generally withdraw permission on their device, which may disable certain features.

Approximate location may also be inferred from an IP address, a selected area or information provided by the user. Retention periods and levels of precision must be proportionate to the purpose.

15. Personalisation, ranking and profiling

Interactions and preferences may be used to order content, propose results or personalise a user journey. Parameters may include the query, context, location, previous choices, availability, data quality, popularity or anti-fraud signals.

Where the law grants a specific right concerning a decision based solely on automated processing that produces legal or similarly significant effects, the applicable safeguards are implemented, including information, the possibility of human intervention or challenge where required.

Most ordinary recommendations of content or products do not necessarily amount to a legal decision about the user.

16. Measurement, analytics and improvement

Technical and statistical measurements may be used to understand usage, detect errors, measure performance and improve the Services. Where those measurements require a cookie or identifier subject to consent, they are enabled only after the required choice.

Where possible, aggregated or pseudonymised data is preferred for analyses that do not require direct identification. Pseudonymised data remains personal data where it can be linked to a person using additional information.

17. Marketing, affiliation and attribution

With the appropriate legal basis, the Publisher may measure the origin of a visit, the effectiveness of a campaign, an affiliate click or a conversion. Technical identifiers may be transmitted to a Partner to attribute a commission or prevent fraud.

Electronic commercial communications are sent only under the conditions permitted by law. An unsubscribe or objection mechanism is provided where required. Strictly operational messages may continue where necessary for the account or a Transaction.

18. Recipients and categories of service providers

Depending on the feature, data may be accessible to authorised teams of the Publisher and to the following categories, only to the extent necessary: hosting and cloud providers, network and security providers, authentication, messaging, support, analytics, payment and fraud prevention, storage, AI, mapping, translation, communications, invoicing, advisers, sellers or service providers involved in a Transaction, and authorities where required by law.

Service providers acting on behalf of the Publisher are subject to appropriate confidentiality, security and processing obligations. A third party acting for its own purposes does not become a processor merely because it is mentioned in this list.

19. Disclosure to third parties, transfer of business and legal obligations

Data may be disclosed where a rule of law, valid decision, a person’s safety, prevention of serious fraud or defence of rights justifies it to the extent authorised.

In the event of a merger, acquisition, restructuring, financing, asset transfer or comparable transaction, certain data may be disclosed to the parties and advisers involved under appropriate safeguards, and then transferred to the successor if the transaction is completed. Required information is provided where legally necessary.

20. International transfers

Infrastructure or certain service providers may process data in countries different from the user’s country. Where applicable law regulates those transfers, the Publisher uses a recognised mechanism or appropriate safeguards, for example an adequacy decision, contractual clauses, binding rules or another relevant legal basis.

The exact location may depend on the Service, provider and region. Additional information about safeguards may be provided where the law grants that right.

21. Retention periods

Data is retained for a period proportionate to the purpose: the duration of the account or contract, time needed for performance and support, dispute periods, accounting or legal obligations, fraud prevention, security and defence of rights.

Different categories therefore have different retention periods. Technical logs may be kept for a shorter period or, in the event of an incident, placed under longer evidentiary retention. Data subject to a legal obligation may be archived even after the account is deleted.

When data is no longer necessary, it is deleted, anonymised or made inaccessible according to a reasonable process, subject to rotating backups and technical constraints.

22. Backups and deletion

Deleting an item in the interface may remove it immediately from ordinary use without erasing it instantly from all backups. Backups are replaced according to their normal cycles and are not used to selectively restore deleted data except where needed for continuity or required by law.

A request for erasure does not apply where retention remains necessary on a basis recognised by applicable law, for example a legal obligation, exercise of rights, fraud, security or freedom of expression in certain contexts.

23. Security

The Publisher implements technical and organisational measures proportionate to the risks, which may include access control, encryption in transit, segregation, logging, backups, secrets management, dependency review, abuse detection, privilege restrictions and incident procedures.

No method of transmission or storage guarantees absolute security. The user must protect their credentials, keep their devices up to date and promptly report suspicious activity. No general promise is made that breaches or attacks will never occur.

24. Security incidents and data breaches

Where an incident affects personal data, the Publisher assesses its nature, scope, affected categories and risks. It takes reasonable containment, remediation and prevention measures.

Authorities and affected individuals are informed where notification is legally required and within the applicable time limits. A communication may be adapted so as not to compromise an investigation or reveal exploitable details, to the extent permitted by law.

25. Rights of individuals

Depending on applicable law, an individual may in particular have rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent, information about certain disclosures of data, recourse against certain automated decisions, or the right to lodge a complaint with an authority.

These rights are not identical in all territories and may be subject to conditions, exceptions or limitations. The Publisher applies the rights actually applicable to the individual’s situation rather than indiscriminately promising every right in every country.

26. Exercising rights and verification

Requests may be submitted using the contact details in the Legal Notice or a dedicated tool. To protect data, the Publisher may request reasonable information to verify identity, the authority of a representative and the scope of the request.

Manifestly unfounded, excessive or repetitive requests may be limited, refused or subject to a reasonable fee only where applicable law permits it. The Publisher documents the basis for a refusal where required.

A request must not require disclosure of data that would adversely affect the rights and freedoms of others. Responses may be redacted or structured accordingly.

27. Objection, unsubscribe and withdrawal of consent

Where processing is based on consent, consent may be withdrawn as easily as reasonably possible through the relevant channel. Withdrawal is not retroactive.

Where a person has a right to object, including to direct marketing, they may exercise it through the available means. An objection to direct marketing does not prevent communications necessary for security, the account or a Transaction.

28. Minors

Services intended for minors implement rules appropriate to age, the nature of the data and applicable consent or parental authorisation requirements. Information intended for minors must be presented in a form understandable to the intended audience where required by law.

The Publisher seeks to limit the collection of unnecessary data concerning children. Legal guardians may use the available mechanisms to exercise the rights granted to them.

If the Publisher learns that data has been collected from a minor in breach of an applicable age or authorisation condition, it may take steps to delete, restrict or regularise the processing.

29. Cookies and similar technologies — definition

The term “cookies” in this Page covers HTTP cookies and, depending on context, local storage, SDKs, pixels, tags, advertising identifiers, device identifiers and comparable technologies that make it possible to store or read information on a device or link events.

The list actually used varies depending on the Service, browser, device, region, enabled integrations and the user’s choices.

30. Categories of cookies

Technologies that may be used include:

31. Consent to cookies and non-essential technologies

Where prior consent is required for a non-essential technology, it is enabled only after a valid choice. Simply continuing to browse is not treated as consent where the law requires a positive action.

The user must be able to refuse or withdraw consent by means that do not make that choice unnecessarily more difficult than acceptance where applicable law so requires.

Cookies strictly necessary for the requested Service or its security may be used without consent where a legal exemption applies, while remaining subject to the relevant information obligations.

32. Managing preferences

Preferences may be managed through a banner, privacy centre, Service, browser or device settings depending on the technology. Refusing non-essential technologies must not prevent access to functions that do not depend on them, except where the law permits a specific consent model.

Deleting browser cookies may also delete the cookie that records a refusal, which may result in a new request for a preference.

33. Third-party cookies and integrations

Embedded third-party content may place or read its own identifiers when loaded. Where consent is required, the integration may remain blocked until the user makes a choice.

Third parties acting for their own purposes are responsible for their processing under their policies. The Publisher selects and configures its integrations reasonably but does not control all independent practices of those third parties.

34. Global preference signals and advertising opt-out

Where applicable law requires recognition of a technical preference or objection signal, such as a recognised global opt-out mechanism, the relevant Service seeks to honour it for covered processing.

The concepts of “sale”, “sharing” or “targeted advertising” vary across jurisdictions. A transfer to a Partner, affiliate system or advertising provider may fall within those concepts in certain regions even if no data is sold in the ordinary sense. Required choices are then offered in accordance with applicable law.

35. Fraud, security and essential cookies

Identifiers or logs may be necessary to detect bots, protect a session, limit attacks, remember a security choice or prevent fraud. Within legal limits, such processing may rely on the necessity of the Service or a security interest rather than advertising consent.

Systematically blocking those mechanisms may make certain functions unavailable or prevent reliable authentication.

36. Changes to the Policy

This Page may be updated to reflect changes to the Services, service providers, practices or applicable rules. The version date is updated.

Where a change materially alters processing and new information, new consent or another action is legally required, the Publisher implements that measure before or at the appropriate time.

37. Contact and complaints

The contact details for the Publisher appear in the Legal Notice. A data protection request should ideally specify the relevant Service and account to facilitate the search.

An individual retains the right to lodge a complaint with the competent supervisory authority where the law applicable to them provides for it. Contacting the Publisher first does not constitute a waiver of that right.

38. Languages

This Policy may be translated. The French version constitutes the drafting source for the corpus, subject to mandatory language and transparency rules. Translations must preserve the full meaning, qualifications, rights and limitations of the source version and must not be summarised.