IRIS / INOVAITE
Privacy policy
Standalone English version — closed IRIS pilot
Last updated: 4 October 2026.
Who are we?
IRIS is a decision-support intelligence solution for recruitment, published by Kamel IRZOUNI, the individual behind the INOVAITE entrepreneurial project currently being established, residing in Perpignan (66000), France, acting as founder and project leader, hereinafter referred to as "INOVAITE" or "we". The publisher's full postal address appears in the non-disclosure agreement (NDA) and the data processing agreement (DPA) sent with the pilot invitation.
Contact for any personal data enquiry: kamel.irzouni@inovaitesolutions.com.
IRIS is currently in a closed pilot phase: access is restricted to invited users, with manually created accounts.
Our two roles
Data controller: for the data of Service users (pilot recruiters) — account, authentication, usage, support, security.
Data processor: for candidate data (CVs, applications) that recruiter users import into IRIS. The recruiter or their organisation remains the controller of that data: they determine the purposes, the essential means and the legal basis of the processing, and we act only on their documented instructions. Where the recruiter itself acts on behalf of a client — recruitment agency or recruitment process outsourcing provider —, it is that client’s processor and we act as sub-processor. The relationship is governed by the data processing agreement (DPA), accepted when the account is activated. Informing candidates, before the analysis, is the recruiter's responsibility; they draft their own notice from the elements set out in the DPA: sub-processors, transfers, applicable safeguards and retention periods.
Data we process
User data (we act as controller):
- identification and account: first name, last name, professional email, identifier;
- login and security data: authentication logs, IP address, timestamps, browser agent;
- usage data: campaigns created, operations performed, quota consumption, operation performance and cost metrics;
- feedback and support: feedback messages, reports of issues;
- evidence of acceptance of the pilot documents: organisation, name, email address, invitation and activation dates, versions and digital fingerprints of the accepted documents.
Candidate data (we act as processor, on the recruiter's instructions):
- CVs and application documents imported by the recruiter (PDF, DOCX, TXT);
- content extracted from those documents and analyses generated by the Service;
- candidate sheets and reports produced for the recruiter.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the Service and managing pilot accounts | Contract performance where the user is personally a party to the pilot terms; otherwise, the legitimate interest of INOVAITE and of the pilot organisation in administering and securing access to the Service |
| Analysing applications and generating outputs for the recruiter | Legal basis determined by the controller, as the case may be the Pilot Recruiter or its client; we act as processor or sub-processor, on its documented instructions |
| Security, logging, abuse prevention, quotas | Legitimate interest (protecting the Service and its users) |
| Technical error monitoring | Legitimate interest (Service reliability) |
| Pilot improvement based on identifiable feedback, then anonymisation or aggregation | Legitimate interest (improving IRIS); once effectively anonymised, feedback no longer falls under the GDPR |
| Retaining evidence of acceptance of the pilot documents (agreements, terms, this policy) | Legitimate interest (establishing and enforcing the commitments made) |
| Compliance with legal obligations | Legal obligation |
Recipients and processors
Data is neither sold nor rented. It is accessible only to authorised INOVAITE personnel and to our technical processors:
| Processor | Role | Location |
|---|---|---|
| Clever Cloud SAS | Application hosting | France (Paris) |
| Supabase | Database, authentication, file storage | Ireland (EU); contracting entity Supabase Pte. Ltd. (Singapore), transfers covered by standard contractual clauses |
| Sentry | Technical error monitoring only — minimised data, with no CV, candidate document or report content by default | Germany (Frankfurt) |
| Cellar (Clever Cloud) | Audit storage and backups | France |
| AI model provider designated in the data processing agreement (DPA), Annex 2 | AI model analysis processing | Processing possible outside the European Union, in particular in the United States, covered by standard contractual clauses |
Retention periods
In accordance with our retention and deletion policy:
- recruiter account: duration of the pilot plus fifteen days;
- CVs and candidate documents: 30 days after pilot access ends;
- reports and analyses: 30 days after pilot access ends;
- campaigns: 30 days after pilot access ends;
- technical logs: 90 days;
- audit logs: 12 months;
- identifiable feedback: 6 months, then anonymised or deleted;
- evidence of acceptance of the pilot documents: five years after the end of the pilot, the ordinary limitation period under French law (Article 2224 of the Civil Code), then deletion.
At the end of these periods, data is irreversibly deleted or anonymised. After deletion from operational environments, some copies may remain in protected backups that are not used in day-to-day operation, until they are overwritten according to the normal rotation cycle and at the latest ninety days after operational deletion.
Security
Key measures: encryption in transit (HTTPS), per-user data isolation at database and storage level, named accounts, access control, logging and audit trail, quotas and rate limiting, private storage buckets, EU hosting environment, private code repository, secrets managed outside the code.
In the event of a personal data breach, the applicable role determines who notifies. Where we act as controller (recruiter user data), we notify the CNIL where such notification is required under GDPR Article 33 and, where applicable, inform the individuals concerned under its Article 34. Where we act as processor (candidate data), we inform the relevant recruiter of any breach affecting the data processed on their behalf, as soon as possible and at the latest forty-eight hours after becoming aware of it; we pass on the information available to us and reasonably assist them in assessing the breach and meeting their obligations. Notification to the supervisory authority and information of the individuals concerned then fall to the controller, as the case may be the recruiter or its client, save for any legal obligation directly applicable to INOVAITE.
Your rights
Depending on the applicable legal basis and under the conditions set out in the GDPR, you have the rights of access, rectification, erasure, restriction and objection, as well as, where it applies, the right to data portability.
Recruiter users: exercise your rights via kamel.irzouni@inovaitesolutions.com.
Candidates: contact first the controller, that is, the organisation that processed your application or on whose behalf it was processed. If you contact us directly, we will forward your request to the relevant recruiter and assist them in responding.
You may lodge a complaint with the CNIL (www.cnil.fr).
Cookies and trackers
IRIS only uses trackers strictly necessary for the operation of the Service (authentication, session, security). No advertising cookies or third-party analytics trackers are used during the pilot. Should this change, this policy will be updated and your consent collected where required.
Changes to this policy
This policy may be updated, in particular at the end of the pilot phase. Active users are informed of any substantial change. The applicable version is the one published on the Service.