Data charter

Last updated: 19 August 2026

1. Company commitment

The Company commits to respect the principles of article 5 Data: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability.

2. Privacy by Design and by Default

In accordance with article 25 Data, data protection is integrated from design and guaranteed by default. Each major evolution undergoes prior review.

3. Records of processing activities

The Company maintains records in accordance with article 30 Data, listing all operations under its responsibility and as processor.

4. Roles

4.1. Controller for directly collected data (prospects, clients, suppliers, candidates, visitors, employees).

4.2. Processor within the meaning of article 28 Data for data deposited by Clients on the Services.

5. Technical measures

6. Organisational measures

7. DPO

The Company has appointed a DPO in accordance with articles 37 to 39 Data. Contact: [email protected].

8. Notification of breaches

The Company documents all breaches and measures taken.

9. DPIA

In accordance with article 35 Data, the Company conducts a prior impact assessment for any processing likely to result in high risk. Reviewed at each substantial evolution, at least every 3 years.

10. International transfers

12. Cooperation with authorities

The Company actively cooperates with supervisory authorities and responds to their requests within the timeframes they impose.

13. Periodic review

The charter undergoes annual review by Management, under the control of the DPO. Any substantial modification is communicated by appropriate means.