Security, Privacy & Compliance
Everything you need to know about how we protect your data and maintain compliance
Legal Documentation
How we collect, use, and protect your personal data
Read PolicyMaster Subscription Agreement and service terms
Read TermsGDPR-compliant data processing framework
Read DPACommon Questions
Quick answers organized by topic
Data Storage & Location
All customer data is stored in the European Union (AWS Paris, eu-west-3). Your data is encrypted at rest with AES-256 and in transit with TLS 1.2+.
Some subprocessors (OpenAI, Stripe) are in the USA. We use Standard Contractual Clausesto ensure GDPR-compliant transfers.
EU (Paris) is the default for all users. Enterprise customers can request alternative regions subject to separate agreement.
Weekly encrypted backups stored in eu region.. 30-day retention period.
We maintain a comprehensive disaster recovery plan with regular testing. Backups are stored in multiple availability zones for redundancy.
Data Access & Privacy
Only your authorized users and your client companies (for submitted candidates). Multi-tenant isolation ensures other agencies cannot see your data.
Only for technical support (with your permission) or legal compliance. All access is logged and audited.
No. We never sell customer data or candidate information to third parties. Your data is yours.
Each agency operates in a completely isolated environment. Agencies cannot access each other's candidate data or see other agencies' activities.
Candidates can delete their profile anytime. Their CV is only visible to agencies they applied through. We comply with GDPR data subject rights.
We don't extract sensitive data (health, race, religion) from CVs unless incidentally present. Customers must ensure compliance with employment laws.
AI & Data Processing
No. OpenAI does not store your CV data or use it to train models per our enterprise agreement. Processing happens in real-time with zero retention.
We send CV text to OpenAI's API to extract structured data (skills, experience, education). The data is processed immediately and not stored by OpenAI.
CV parsing, semantic search, candidate-job matching, interview question generation, and CV optimization recommendations.
AI systems may contain bias. We don't warrant AI is bias-free. Customers must implement human oversight for hiring decisions and comply with anti-discrimination laws.
No. AI scores are recommendations only. Human recruiters make all final hiring decisions. You must validate AI outputs before acting.
Transcripts are created with consent and retained per your agency's policy. You can request deletion anytime.
Data Retention & Deletion
Indefinitely while your account is active. You control retention - delete documents anytime through account settings.
Accounts inactive for 6 months will be deleted. We notify you 30 days before deletion. Login to prevent deletion.
Yes. Request deletion at bg@floreal.ai. Removed from active systems within 2 business days. Backups deleted within 7 days.
90-day retrieval period to export your data. After 90 days, data is automatically deleted (or earlier on request).
Use built-in export functionality (JSON, CSV format) or request a database dump at bg@floreal.ai.
Only if required by law (tax, accounting). Anonymized audit logs may be retained for compliance. All other data is permanently deleted.
Security Measures
TLS 1.2+ for data in transit. AES-256 for data at rest. All database connections encrypted.
Role-based access control (RBAC), automatic session timeout, API authentication with secure tokens, and principle of least privilege.
AWS EU infrastructure, DDoS protection (AWS Shield).
Third-party penetration testing, automated vulnerability scanning, code reviews before deployment, protection against OWASP Top 10 : Q1 2026.
Working toward SOC 2 Type II certification (target within 6 months). Also pursuing ISO 27001.
Regular security training, confidentiality agreements, background checks for staff with data access, incident response drills.
Data Breaches & Incidents
We notify you within 24 hours via email with details about what happened, what data was affected, and our response actions.
Nature of incident, types of data affected, number of people impacted, immediate actions taken, and contact for questions.
Immediate containment, thorough investigation, root cause remediation, rolling updates to customers, notification to authorities if required.
Yes. Comprehensive incident response procedures with 24-hour breach notification.
Yes, within 72 hours if required by GDPR. We'll also assist with your own notification obligations.
Legal Rights (GDPR & CCPA)
Access, rectification, erasure ("right to be forgotten"), restriction, data portability, object to processing, withdraw consent.
Right to know what data we collect, right to delete, right to opt-out of sale (we don't sell data), right to non-discrimination.
Email bg@floreal.ai or use account settings. We respond within 30 days (GDPR)or 45 days (CCPA).
Yes (Right of Access). Request at bg@floreal.ai or export via account settings. Provided in JSON or CSV format within 30 days.
Yes (Right to Data Portability). We provide data in machine-readable format (JSON, CSV) for transfer to another controller.
Yes, you can object to processing based on legitimate interests. For direct marketing, we honor objections immediately.
Contact us at bg@floreal.ai first. You can also file a complaint with your local data protection authority (CNIL in France, ICO in UK).
Subprocessors & Third Parties
AWS (hosting), OpenAI (AI), Pinecone (search), Stripe (payments), Customer.io (email), Twilio (phone), BAAS (transcription), Gladia (audio).
To provide specialized services (cloud hosting, AI processing, payments) more efficiently than building in-house.
Yes. All subprocessors sign Data Processing Agreements (DPAs) with Standard Contractual Clauses for international transfers.
Yes. We notify you 30 days before adding new subprocessors. You have 15 days to object on reasonable data protection grounds.
Visit /subprocessors
Compliance & Certifications
Yes. We comply with GDPR, including data subject rights, security requirements, breach notification, and international transfer safeguards.
Yes. We comply with CCPA as a Service Provider. We don't sell personal data and honor all California consumer rights.
Yes. Benjamin Gabay, 30 rue René Boulanger, 75010 Paris, France. Email: bg@floreal.ai
Working toward SOC 2 Type II and ISO 27001 (target within 6 months). Currently conducting annual penetration testing.
Yes. Contact bg@floreal.ai for security documentation, compliance summaries, or to schedule an audit (once per year with 30 days notice).
Benjamin Gabay, EU Representative. Email: bg@floreal.ai. Response time: 3-5 business days.
Platform Usage
Essential cookies (authentication, security), analytics cookies (Google Analytics, Customer.io), and preference cookies (language, UI settings).
Yes, for non-essential cookies. Use browser settings or our cookie consent banner. Essential cookies required for service operation.
We collect usage data (pages visited, features used, search queries) for analytics and platform improvement. IP addresses may be used by google analytics only on the non logged part.
API access logs, error logs, security event logs, audit trails. CloudWatch logs retained 14 days. Audit trails retained for compliance (7 years).
Search results cached for 30 days, then automatically expired. No permanent storage of search queries.
Still Have Questions?
Contact our Data Protection Officer