Privacy policy & GDPR
This policy describes how SARL DomicileGO France (hereinafter the “Controller”) collects, uses, stores and protects personal data of visitors and applicants, in compliance with the GDPR (EU Regulation 2016/679) and the French “Informatique et Libertés” Act No. 78-17 of 6 January 1978, as amended.
1. Data we collect
We only collect data that is strictly necessary for the stated purposes: full name; age; gender; phone number (WhatsApp); e-mail address (if provided); subject and content of your message (contact form). Technical data collected automatically: IP address (pseudonymised whenever possible), device type, User-Agent, preferred language — exclusively for security purposes (abuse detection) and audience analytics.
2. Purposes and legal basis of processing
Data is processed on the following legal grounds: (a) your explicit consent (Art. 6(1)(a) GDPR) when you submit the form — to contact you on WhatsApp and share job offers matching your profile; (b) the performance of pre-contractual measures (Art. 6(1)(b) GDPR) — during a concrete connection with an employer; (c) the Controller’s legitimate interest (Art. 6(1)(f) GDPR) — website security and anti-spam protection; (d) a legal obligation (Art. 6(1)(c) GDPR) — accounting and tax record keeping.
3. Retention period
Data from an online application is retained for 3 years from the last contact with the candidate, unless you exercise your right to erasure earlier. After this period, data is either anonymised for statistical purposes or securely deleted. Technical log data is kept for a maximum of 12 months.
4. Recipients and transfers outside the EU
Your data is never sold to third parties. It is only accessible to authorised staff of SARL DomicileGO France (recruiters, DPO) and to contracted technical service providers (hosting, internal CRM). No personal data is transferred to a third country outside the European Union without appropriate safeguards (European Commission Standard Contractual Clauses).
5. Data security
We implement organisational and technical measures in accordance with Article 32 of the GDPR: data encryption in transit (TLS 1.2+ / HTTPS HSTS); daily encrypted backups; role-based access control with unique passwords; regular staff awareness training; access logging (audit trail).
6. Your rights as a data subject
You may exercise the following rights at any time: right of access and to a copy of your data; right to rectification; right to erasure (“right to be forgotten”); right to restriction of processing; right to data portability; right to object; right to issue post-mortem directives; right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. To exercise your rights, please contact us at the address listed below. Response time: 1 month, extendable by 2 additional months in case of complex requests. Right to lodge a complaint with the CNIL (France) or your local supervisory authority.
7. Cookies and trackers
The site uses ONLY strictly necessary cookies for its operation (PHPSESSID session cookie, site_lang language preference cookie). No advertising cookies, no third-party trackers (Google Analytics, Meta Pixel, etc.) are placed without your prior explicit consent. You can block cookies via your browser settings; some features may then become unavailable.
8. Contact details and DPO
For any question about your data or to exercise your rights, please send your request (with a copy of your ID for access / erasure requests) to:
Last updated: July 2025