Data Protection

Privacy Privacy Policy

Data Processed, Legal Bases, Retention Periods, Processors, and Data Subjects’ Rights.

Hosting in the European Union·GDPR-compliant
Updated: February 14, 2026

1Introduction

MR SURICATE particular importance on the protection of personal data and respect for the privacy of the individuals concerned.

As part of its business activities, MR SURICATE collects and processes personal data, including data relating to:

  • its professional prospects and clients
  • the users of its SaaS platform
  • its suppliers and partners
  • job applicants
  • visitors to its websites

MR SURICATE that the collection and processing of this data are carried out in accordance with Regulation (EU) 2016/679 of April 27, 2016 (GDPR) and the amended French Data Protection Act.

Committed to building lasting relationships based on trust and transparency, MR SURICATE appropriate technical and organizational measures to ensure an adequate level of protection for the personal data it processes.

The purpose of this policy is to consolidate clear, precise, and accessible information regarding the data processing activities carried out by MR SURICATE into a single document.

MR SURICATE
7 rue Mathurin Brissonneau
, 44100 Nantes – France

2. The Roleof MR SURICATE Treatments

Depending on the situation, MR SURICATE step in:

As Data Controller

MR SURICATE as the Data Controller for data relating to:

  • Sales management and B2B prospecting
  • Customer relationship management
  • Administrative support
  • Recruitment
  • Compliance with legal and regulatory obligations

In this context, MR SURICATE the purposes and means of data processing.

As Data Processor

Test scenarios generally utilize test data sets provided or validated by the client.

Depending on the configuration chosen by the client, certain processing operations may, however, involve personal data under the client's responsibility.

In this situation:

  • The Client acts as Data Controller
  • MR SURICATE as a subcontractor

These processing operations are contractually governed by a specific Data Processing Agreement (DPA).

3. Categoriesof Processed Data

Depending on the situation, MR SURICATE handle, among other things:

  • identification data (name, first name)
  • professional contact details (email, company)
  • connection data and technical logs
  • information related to platform usage
  • application data (CV, professional experience)

4PrinciplesGoverning Data Processing

MR SURICATE to upholding the fundamental principles of the GDPR.

Determined and Legitimate Purpose

Personal data is collected for specified, explicit, and legitimate purposes, including:

  • Provision and Operation of the SaaS Platform
  • User Account Management
  • Technical Support
  • Invoicing
  • System Security and Monitoring
  • B2B Commercial Communication
  • Application Management
  • Compliance with Legal Obligations

Data is not subsequently processed in a manner incompatible with these purposes.

Data Minimization

MR SURICATE that it collects only the data strictly necessary for the intended purpose.

The data collected is:

  • Relevant
  • Adequate
  • Limited to what is necessary

Accuracy and Updates

MR SURICATE reasonable measures to ensure that the data is accurate and, when necessary, kept up to date.

Storage Limitation

Data is retained only for the period necessary to fulfill the processing purposes and in compliance with applicable legal obligations.

By way of indication:

  • Prospect data: 3 years after the last contact
  • Client data: duration of the contractual relationship
  • Technical logs: 12 months
  • Application data: maximum 2 years

5Legal Basisfor Data Processing

The processing operations implemented are based on one of the following legal grounds:

  • Performance of a contract or pre-contractual measures
  • The Legitimate Interest of MR SURICATE
  • The consent of the data subject when required
  • Compliance with a legal obligation

6. Housingand Safety

The MR SURICATE platform MR SURICATE hosted on Google Cloud Platform, in the europe-west1 (Belgium) region, with a multi-zone deployment.

MR SURICATE appropriate technical and organizational measures, including:

  • Encryption of data at rest (AES-256)
  • Encryption of data in transit (TLS)
  • Access management based on the principle of least privilege
  • Multi-factor authentication for privileged accounts
  • Logging of access and security events
  • Daily Backups
  • Indicative RPO (24h) and RTO (8 business hours) Objectives

These measures are integral to an Information Security Management System structured in accordance with ISO 27001 principles.

They fall under a reinforced obligation of means.

7Subcontractorsand Transfers

MR SURICATE use technical subcontractors (cloud hosting, communication services, DNS services, device farms, etc.). The list of subcontractors used by MR SURICATE available in the document titled "Subprocessors List."

These subprocessors:

  • Are selected based on appropriate security guarantees
  • Are contractually bound
  • Are subject to regular evaluation

In the event of data transfers outside the European Union, MR SURICATE that appropriate safeguards are in place (standard contractual clauses or equivalent mechanisms).

8Incident Management

MR SURICATE a formalized incident management procedure that includes:

  • Detection
  • Qualification
  • Containment
  • Remediation
  • Notification without undue delay when necessary
  • Post-incident Analysis

In the event of a personal data breach, obligations stipulated by the GDPR and contractual commitments are adhered to.

9Artificial Intelligence

Certain platform functionalities may incorporate AI-powered assistance mechanisms.

These mechanisms:

  • Are designed as technical assistance tools
  • Remain under human supervision
  • Do not make automated legal decisions
  • Are integrated into the ISMS risk analysis.

The governance of these mechanisms is described in a separate AI Governance Statement.

10. Rightsof Data Subjects

In accordance with the GDPR, individuals possess the following rights:

  • Right of access
  • Right to Rectification
  • Right to Erasure
  • Right to Restriction of Processing
  • Right to Object
  • Right to Data Portability
  • Right to Withdraw Consent
  • Right to Lodge a Complaint with the CNIL

Requests may be submitted to: dpo@mrsuricate.com

A response will be provided within one month, except in cases of particular complexity.

11Safetyand Shared Responsibility

The security of personal data is based on a shared responsibility model:

  • MR SURICATE the security of its platform and infrastructure.
  • Clients and users are responsible for managing their own access and configuring their internal environments.

12Data Protection Contact

For any questions regarding personal data protection or for exercising the rights stipulated by the GDPR: dpo@mrsuricate.com

13Policy Update

This policy may be amended to reflect:

  • Regulatory developments
  • Technological advancements
  • Organizational changes

The update date is indicated in the header.

Do you have a question about your data?

All requests to exercise your rights or to obtain information about our data processing should be sent to this address.