Privacy Policy
Gisel acts as a data processor within the meaning of the GDPR. Our clients remain the data controllers responsible for the processing of their consultants' and candidates' personal data.
1Who We Are
Gisel is a B2B SaaS solution that enables IT consulting companies, recruitment firms and freelancers to create and manage professional profiles based on CVs. We collect and process this data solely on behalf of our clients and only to the extent necessary to provide our services.
2The Data We Collect
We collect our clients' account information, including name, professional email address and company name. We also process CVs and professional information relating to consultants and candidates uploaded to the platform, subscription and billing information, as well as technical and connection logs required to maintain the security and proper operation of the platform.
3How We Process CVs Depending on How You Use Gisel
When using Gisel without the CV Library, an uploaded CV is processed only for the time required to generate the professional profile. It is then automatically deleted once you have downloaded the generated document, or within 24 hours at the latest. When using Gisel with the CV Library, CVs remain stored in your account until you choose to delete them. You remain in control of how long your CV database is retained.
4Your Control Over Data Deletion
You can delete an individual CV or document, remove a consultant's complete profile, or delete your entire CV Library database in a single action. These deletions can be performed directly from your account or upon request to our team.
5Export Your Data Whenever You Need It
You can export your CVs, generated professional profiles and custom templates at any time. Data export is available throughout your subscription and in the event of cancellation.
6Where Your Data Is Hosted
All our infrastructure is hosted in France by OVHcloud. No data is stored or processed outside France or the European Union, helping ensure compliance with the GDPR.
7How We Protect Your Data
Your data is encrypted in transit using HTTPS/TLS and encrypted at rest using AES-256 encryption. Access to the platform is protected by authentication, and access rights are segmented by organization. We also perform regular and secure backups of our databases.
8What We Commit Never to Do
We do not sell or rent your data to third parties. We never use your consultants' or candidates' CVs or personal data to train artificial intelligence models. We access your data only when strictly necessary to provide the service or to perform technical support explicitly requested by you.
9Your Rights Under the GDPR
In accordance with the GDPR, you may have the right to access, rectify, erase and obtain the portability of your personal data, as well as the right to object to or restrict certain processing activities. To exercise any of these rights, contact us at contact@gisel.io.
10Our Service Providers
We use OVHcloud to host our infrastructure in France. A complete and up-to-date list of our subprocessors is available upon request.
11In the Event of a Data Breach
If a security incident affects your data, we will inform you without undue delay so that you can meet your own regulatory obligations where applicable. Where required by applicable data protection law, personal data breaches presenting a relevant risk will be notified to the competent supervisory authority within the applicable regulatory timeframe, including the 72-hour period provided for under the GDPR.
12Data Processing Agreement (DPA)
We provide a Data Processing Agreement compliant with Article 28 of the GDPR to clients who require one. You can request a copy by contacting us at contact@gisel.io.
Une question sur notre politique de confidentialité ?
Contact our team at contact@gisel.io