Privacy Policy
The protection of your personal data is a priority for INSIAC. This policy informs you how we collect, use and protect your data in accordance with the General Data Protection Regulation (GDPR).
Effective date: 1 January 2025 · Last updated: June 2025
1. Identity of the Data Controller
The controller of personal data collected via insiac.fr and associated services is:
INSIAC SAS
50 Avenue des Champs-Élysées, 75008 Paris, France
Email: contact@insiac.fr
Phone: 07 56 44 46 87
By using our services, you accept the practices described in this policy. If you do not accept these practices, please refrain from using our services.
2. Data Collected
We collect the following categories of data depending on the context of use:
Registration and account creation
- First and last name
- Email address
- Phone number
- Date of birth
- Nationality
- Password (encrypted)
Application file
- Curriculum Vitae (CV)
- Cover letter
- Qualification certificates and transcripts
- Identity document
- Passport photo (optional)
- Proof of address
Payment (via Stripe)
- Bank card details (processed directly by Stripe, not stored by INSIAC)
- Transaction history
- Billing address
Browsing and technical data
- IP address
- Browser type and operating system
- Pages visited and visit duration
- Cookies (see dedicated section)
3. Purposes of Processing
Your personal data is processed for the following purposes:
Managing applications and the admission process
Creating and managing the student account on our portal
Invoicing and managing tuition fee payments
Communication related to your programme (timetables, grades, events)
Sending information about our programmes and events (with consent)
Improving our services and website (anonymised statistics)
Compliance with our legal and regulatory obligations
4. Legal Basis for Processing
Consent (Art. 6.1.a GDPR)
For marketing communications and non-essential cookies.
Contractual performance (Art. 6.1.b GDPR)
For managing enrolments, payments and access to programmes.
Legitimate interest (Art. 6.1.f GDPR)
For improving our services, fraud prevention and IT security.
Legal obligation (Art. 6.1.c GDPR)
For compliance with accounting, tax and regulatory obligations.
5. Data Retention Periods
Your data is retained for the following periods:
| Data category | Retention period |
|---|---|
| Application file (not admitted) | 2 years after the decision |
| Active student data | Duration of programme + 5 years |
| Post-graduation data | 5 years after graduation |
| Billing data | 10 years (legal accounting obligation) |
| Prospecting data (marketing) | 3 years after last contact |
| Analytical cookies | 13 months maximum |
6. Data Sharing
INSIAC never sells your personal data to third parties for commercial purposes. Your data may only be shared with:
Stripe
Secure payment provider — only data necessary for the transaction. Stripe is PCI-DSS certified.
OVHcloud
Data host in France (Roubaix and Gravelines data centres). Subject to French and European law.
Competent authorities
Upon legal request from French judicial, police or tax authorities.
We do not transfer data outside the European Union without appropriate safeguards.
7. Your GDPR Rights
In accordance with the GDPR, you have the following rights:
Right of access
Obtain a copy of your personal data.
Right of rectification
Correct inaccurate or incomplete data.
Right of erasure
Request deletion of your data (right to be forgotten).
Right to portability
Receive your data in a structured, readable format.
Right to object
Object to processing of your data for marketing purposes.
Right to restriction
Request temporary suspension of processing.
How to exercise your rights?
Send your request by email to our DPO: dpo@insiac.fr. Attach a copy of an identity document. We will respond within one month. If the response is unsatisfactory, you may contact the CNIL: www.cnil.fr.
8. Cookie Policy
Our site uses several categories of cookies. Strictly necessary cookies are set without your consent. Others require your explicit agreement via our consent banner.
| Type | Purpose | Consent |
|---|---|---|
| Necessary | Session, security, authentication | Not required |
| Analytical | Traffic measurement (anonymised statistics) | Required |
| Functional | Remembering your preferences (language, theme) | Required |
9. DPO Contact
Data Protection Officer (DPO)
Email: dpo@insiac.fr
Postal address: DPO INSIAC SAS, 50 Avenue des Champs-Élysées, 75008 Paris, France
You also have the right to lodge a complaint with the competent supervisory authority, the CNIL (Commission Nationale de l'Informatique et des Libertés), at www.cnil.fr.
10. Updates to This Policy
INSIAC SAS reserves the right to modify this privacy policy at any time to reflect changes in law, regulation or our practices. In the event of a substantial change, we will inform you by email (if you are registered) or via a notice on the site.
The current version is always accessible on this page with its update date. We encourage you to review it regularly.