RGPD / GDPR

    Privacy Policy

    The protection of your personal data is a priority for INSIAC. This policy informs you how we collect, use and protect your data in accordance with the General Data Protection Regulation (GDPR).

    Effective date: 1 January 2025 · Last updated: June 2025

    1. Identity of the Data Controller

    The controller of personal data collected via insiac.fr and associated services is:

    INSIAC SAS

    50 Avenue des Champs-Élysées, 75008 Paris, France

    Email: contact@insiac.fr

    Phone: 07 56 44 46 87

    By using our services, you accept the practices described in this policy. If you do not accept these practices, please refrain from using our services.

    2. Data Collected

    We collect the following categories of data depending on the context of use:

    Registration and account creation

    • First and last name
    • Email address
    • Phone number
    • Date of birth
    • Nationality
    • Password (encrypted)

    Application file

    • Curriculum Vitae (CV)
    • Cover letter
    • Qualification certificates and transcripts
    • Identity document
    • Passport photo (optional)
    • Proof of address

    Payment (via Stripe)

    • Bank card details (processed directly by Stripe, not stored by INSIAC)
    • Transaction history
    • Billing address

    Browsing and technical data

    • IP address
    • Browser type and operating system
    • Pages visited and visit duration
    • Cookies (see dedicated section)

    3. Purposes of Processing

    Your personal data is processed for the following purposes:

    Managing applications and the admission process

    Creating and managing the student account on our portal

    Invoicing and managing tuition fee payments

    Communication related to your programme (timetables, grades, events)

    Sending information about our programmes and events (with consent)

    Improving our services and website (anonymised statistics)

    Compliance with our legal and regulatory obligations

    4. Legal Basis for Processing

    Consent (Art. 6.1.a GDPR)

    For marketing communications and non-essential cookies.

    Contractual performance (Art. 6.1.b GDPR)

    For managing enrolments, payments and access to programmes.

    Legitimate interest (Art. 6.1.f GDPR)

    For improving our services, fraud prevention and IT security.

    Legal obligation (Art. 6.1.c GDPR)

    For compliance with accounting, tax and regulatory obligations.

    5. Data Retention Periods

    Your data is retained for the following periods:

    Data categoryRetention period
    Application file (not admitted)2 years after the decision
    Active student dataDuration of programme + 5 years
    Post-graduation data5 years after graduation
    Billing data10 years (legal accounting obligation)
    Prospecting data (marketing)3 years after last contact
    Analytical cookies13 months maximum

    6. Data Sharing

    INSIAC never sells your personal data to third parties for commercial purposes. Your data may only be shared with:

    Stripe

    Secure payment provider — only data necessary for the transaction. Stripe is PCI-DSS certified.

    OVHcloud

    Data host in France (Roubaix and Gravelines data centres). Subject to French and European law.

    Competent authorities

    Upon legal request from French judicial, police or tax authorities.

    We do not transfer data outside the European Union without appropriate safeguards.

    7. Your GDPR Rights

    In accordance with the GDPR, you have the following rights:

    Right of access

    Obtain a copy of your personal data.

    Right of rectification

    Correct inaccurate or incomplete data.

    Right of erasure

    Request deletion of your data (right to be forgotten).

    Right to portability

    Receive your data in a structured, readable format.

    Right to object

    Object to processing of your data for marketing purposes.

    Right to restriction

    Request temporary suspension of processing.

    How to exercise your rights?

    Send your request by email to our DPO: dpo@insiac.fr. Attach a copy of an identity document. We will respond within one month. If the response is unsatisfactory, you may contact the CNIL: www.cnil.fr.

    8. Cookie Policy

    Our site uses several categories of cookies. Strictly necessary cookies are set without your consent. Others require your explicit agreement via our consent banner.

    TypePurposeConsent
    NecessarySession, security, authenticationNot required
    AnalyticalTraffic measurement (anonymised statistics)Required
    FunctionalRemembering your preferences (language, theme)Required

    9. DPO Contact

    Data Protection Officer (DPO)

    Email: dpo@insiac.fr

    Postal address: DPO INSIAC SAS, 50 Avenue des Champs-Élysées, 75008 Paris, France

    You also have the right to lodge a complaint with the competent supervisory authority, the CNIL (Commission Nationale de l'Informatique et des Libertés), at www.cnil.fr.

    10. Updates to This Policy

    INSIAC SAS reserves the right to modify this privacy policy at any time to reflect changes in law, regulation or our practices. In the event of a substantial change, we will inform you by email (if you are registered) or via a notice on the site.

    The current version is always accessible on this page with its update date. We encourage you to review it regularly.

    We use cookies to make our site work, remember your preferences, and (with your consent) measure site traffic. Cookie policy