Privacy policy
Version 1.6 — last updated 15 September 2026
Courtesy English translation. The French version is legally binding.
1. Who is responsible?
For visitor, prospect, recruiter-account and billing data, the controller is Axel Gilbert, sole trader, SIREN 923 027 155, 5 rue Valentina Terechkova, 31400 Toulouse (see legal notice), reachable at aikip.fr/contact. For candidate data managed in a client workspace, the client company is the controller and aiKip acts as its processor under the public Data Processing Agreement.
2. Data and purposes
- Visitors and prospects: business contact details, company, role, contact messages, commercial exchanges and limited first-party audience data, to answer requests, follow up commercial relationships and improve public pages.
- Recruiter users: identity, business email, profile photo, locale, authentication events, IP address, approximate connection country, browser information, sessions, security logs and support messages, to provide and secure accounts.
- Customer companies: identity, branding, career-page content, legal and billing information, plan, payment-provider identifiers and invoices, to perform and administer the subscription.
- Candidates: contact details, CV or DOCX, cover letter, screening answers, messages, application history, interview proposals and feedback, recruiter notes, extracted career information and AI-assisted scores/explanations, to manage recruitment for the client.
Required and optional fields are identified in the relevant form. aiKip does not request special-category data; candidates should not include information unrelated to professional aptitude.
3. Legal bases
- Recruiter account and subscription: performance of the contract and pre-contractual steps.
- Security, fraud prevention and support: legitimate interests.
- Contact requests: pre-contractual steps when requesting an offer; legitimate interests for other enquiries and proportionate business relationship follow-up. You can object to commercial follow-up through the contact form.
- Optional audience measurement on public pages, in the application and candidate spaces: prior consent, withdrawable through Audience preferences or the control below.
- Invoices and accounting archive: legal obligation.
- Core application receipt and classification: pre-contractual steps requested by the candidate; the client determines and documents the appropriate basis for further assessment, including AI-assisted analysis.
- Future-opportunity talent pool: the candidate’s separate, optional and revocable consent where selected.
Submitting an application does not turn a mandatory checkbox into consent. The displayed notice version and time are recorded as evidence of information.
4. Recipients, processors and location
Access is limited to authorized members of the relevant client and authorized aiKip personnel where support or security requires it. aiKip relies on Scaleway SAS (France: application, database, object storage and Generative APIs for CV analysis) and Mollie B.V. (Netherlands: payments and billing identifiers). Data covered by the service is processed in the European Union. The contractual list and change procedure appear in the DPA.
5. Retention
- Public contact requests and their replies: up to 12 months after resolution. Open requests are reviewed monthly and closed when no longer needed.
- Prospect CRM data: up to 3 years after collection or the last contact initiated by the prospect. Internal notes and our outgoing reminders do not extend this period. Customer relationship records are retained during the relationship, then reviewed and removed within 3 years of its end or the last incoming contact. These records are reviewed manually each month; their deletion is not automated.
- Only evidence necessary for an identified dispute or a legal obligation may be retained separately for the applicable period. Routine contact histories are not accounting archives.
- Recruiter and operational company data: contract term, then 30 days in read-only/export mode, then deletion.
- Candidate data: until the client’s configured or requested deletion and, by default, no longer than 24 months after the last documented interaction, then comprehensive anonymization.
- Invoices and their accounting snapshot: 10 years from the end of the financial year, in an isolated legal archive.
- Minimal contract-acceptance evidence (company, user email, document version and timestamp): 5 years after account deletion, in an isolated legal archive.
- Authentication security events (IP address, approximate country and browser): 90 days. Other security and technical logs: up to 12 months unless an incident requires longer evidence.
- Audience measurement: events and pseudonymous sessions up to 395 days. Audience consent or refusal: 6 months.
- Expired sessions, reset links, verification links and rate-limit records: deleted automatically after their operational lifetime.
6. Your rights
Depending on the legal basis, you may request access, rectification, erasure, restriction, portability or objection and withdraw consent at any time without affecting prior processing. Candidates can use their secure tracking space or contact the relevant recruiting company; aiKip assists that company. You may also contact aikip.fr/contact. A response is normally provided within one month. You can lodge a complaint with the CNIL.
7. AI-assisted analysis
aiKip provides decision support and does not make hiring decisions. Authorized recruiters must review the application and can disregard the score. Criteria, limitations, candidate rights and human-oversight safeguards are described on the AI Transparency page.
8. Cookies and audience measurement
aiKip uses cookies necessary for authentication and requested interface preferences. Optional first-party audience measurement on public pages, in the recruiter application and candidate spaces requires your prior consent, without affecting access or recruitment. No audience cookie is set and no audience event is sent before acceptance. It records pseudonymous sessions of up to 30 minutes and page categories, without account identifiers, candidate content or private URL parameters. The three audiences have separate session identifiers. Audience data stays in France and is not linked to recruiter accounts or candidate files. Individual jobboard journey attribution is paused until a dedicated consent flow is available; signed job links remain usable. Existing attribution identifiers are not reused. The control below disables audience measurement and removes its current browser identifiers and associated sessions; enabling it authorizes optional measurement too. Choices apply to this browser and domain and can also be changed using Audience preferences. Consent or refusal for optional measurement is remembered for 6 months. Sessions and events are retained for up to 395 days. No advertising or third-party analytics cookie is set.
9. Security and changes
aiKip applies access control, tenant isolation, encrypted transport, password hashing, short-lived document links, backups and incident procedures. Material policy changes are dated and, where they affect an existing contract, notified under the Terms of Sale.
Agency workspaces and client presentations
For an agency workspace, the subscribing agency determines the purposes of its candidate processing and instructs aiKip as processor. The agency identifies the client recipient and explains the applicable recruitment basis; the client’s own processing responsibilities depend on the mandate and actual decisions. Before disclosure, the candidate separately authorizes the fixed presentation for that named client. Talent-pool permission is separate. Dossiers can contain selected qualifications, a recruiter summary and, only when selected, a CV and contact details. Client contacts, hashed sign-in/session tokens, mission grants, feedback and access events support restricted collaboration. Guest sign-in links last 15 minutes, sessions 12 hours, mission grants 90 days and presentation access at most 30 days, capped by candidate retention. Expired dossier copies and feedback are purged 60 days after expiry or earlier with underlying candidate/tenant deletion; access events last 90 days. Client views do not restart the candidate inactivity clock. Candidates can inspect and revoke dossiers in their account and export recipient history. Revocation prevents future portal access but cannot erase copies held by recipients, whom the agency must instruct and assist with rights requests.