Data protection policy
Last updated: 11 September 2026
1. Introduction
TIOS Team SAS is the controller of the personal data processed through this website. This policy explains what we collect when you visit it, why, for how long we keep it, and how you can exercise your rights under the General Data Protection Regulation and the French Data Protection Act.
It covers this website only. Personal data processed in the course of a client engagement is governed by the contract signed with that client.
2. Fair collection
We collect personal data in two ways: when you send it to us yourself, by writing to the address published on this site, and automatically as you browse, through a first-party measurement of page views described below. We do not buy contact lists and we do not use third-party advertising cookies.
3. Data we collect
When you write to us. The content of your message and the address you sent it from — including a CV and covering letter, if you are applying for a role.
When you browse. The page visited, the referring domain, the country and the device type inferred from your request, and a random identifier stored in your browser so that repeat visits can be counted without identifying you. We do not store your IP address in this measurement. Before a page address is stored, it is reduced to one of a closed list of recognised page templates — anything else is recorded as « unknown » — so that no identifier contained in a URL reaches our own records. This reduction applies to what we store; it cannot apply to the request your browser makes, which carries the full address to our hosting provider (section 4).
When you use the client area. A session cookie that keeps you signed in, and the account details you have provided.
4. Cookies and similar technologies
This site sets two cookies, both strictly necessary and both first-party: tios_session, which keeps you signed in to the client area, and locale, which remembers your language preference. Neither is used for advertising or shared with advertising networks.
The visitor identifier used for audience measurement is not a cookie: it is a random value stored in your browser, which you can clear at any time by clearing your browsing data.
Our hosting provider receives the full address of every page you request — that is how any web request works — and keeps it in its own server logs under its retention policy. It also produces page-performance measurements for us; the script that collects them is served by that provider, and we identify pages to it by route template rather than by their full address.
5. Why we process it
To answer the messages you send us, and to consider applications for the roles we advertise. The legal basis is our legitimate interest in responding to enquiries, or the steps taken at your request before entering a contract.
To understand how the site is used and to keep it working — measuring traffic in aggregate, detecting errors, and maintaining security. The legal basis is our legitimate interest in operating a reliable site.
To provide the client area to those who have an account. The legal basis is the performance of the contract with that client.
6. Who receives it
Personal data collected through this site is accessible to the members of our team who need it for the purposes above. We also rely on service providers acting on our instructions: our hosting and platform provider, our database provider, and our email delivery provider. They are bound by contract to process the data only on our behalf.
We do not sell personal data, and we do not share it with third parties for their own marketing.
7. Where it is stored
This site is served from our hosting provider's Frankfurt region, and its database is located in the European Union. Some of our providers are companies established outside the European Union; where that leads to a transfer, it takes place under the safeguards permitted by the GDPR, such as an adequacy decision or the European Commission's standard contractual clauses.
8. How long we keep it
Audience measurement records are deleted automatically after thirteen months, by a job that runs every day. Thirteen months allows a year-on-year comparison and no more.
Messages you send us are kept for as long as needed to deal with them, and then for the period required to establish or defend a legal claim. Applications are kept for two years from our last contact with you, unless you ask us to delete them sooner. Client-area accounts are kept for the duration of the contract.
9. How we protect it
The site is served exclusively over HTTPS, with strict transport security. The session cookie is inaccessible to scripts. A content security policy restricts what the browser is allowed to load. Access to the database is limited to the services that need it.
No system is perfectly secure, and we do not claim otherwise. If a breach were to affect your rights, we would notify the supervisory authority and, where required, you.
10. Your rights
You may ask us for access to your personal data, and for its correction, deletion or portability. You may ask us to restrict or to stop a processing that relies on our legitimate interest, and you may set instructions for what happens to your data after your death.
Write to contact@tios.team and we will answer within one month. We may need to check your identity before acting. If you believe we have not handled your request properly, you may lodge a complaint with the CNIL, the French supervisory authority.
11. Changes to this policy
We may update this policy as the site changes. The date at the top of this page tells you when it was last revised.
© 2026 TIOS Team SAS — Paris. All rights reserved.