← Back to IRIS FR
IRIS

IRIS / INOVAITE

Privacy policy

Standalone English version — closed IRIS pilot

Version5.6
Date4 October 2026
StatusClosed pilot

Last updated: 4 October 2026.

01Who are we?

IRIS is a decision-support intelligence solution for recruitment, published by Kamel IRZOUNI, the individual behind the INOVAITE entrepreneurial project currently being established, residing in Perpignan (66000), France, acting as founder and project leader, hereinafter referred to as "INOVAITE" or "we". The publisher's full postal address appears in the non-disclosure agreement (NDA) and the data processing agreement (DPA) sent with the pilot invitation.

Contact for any personal data enquiry: kamel.irzouni@inovaitesolutions.com.

IRIS is currently in a closed pilot phase: access is restricted to invited users, with manually created accounts.

02Our two roles

Data controller: for the data of Service users (pilot recruiters) — account, authentication, usage, support, security.

Data processor: for candidate data (CVs, applications) that recruiter users import into IRIS. The recruiter or their organisation remains the controller of that data: they determine the purposes, the essential means and the legal basis of the processing, and we act only on their documented instructions. Where the recruiter itself acts on behalf of a client — recruitment agency or recruitment process outsourcing provider —, it is that client’s processor and we act as sub-processor. The relationship is governed by the data processing agreement (DPA), accepted when the account is activated. Informing candidates, before the analysis, is the recruiter's responsibility; they draft their own notice from the elements set out in the DPA: sub-processors, transfers, applicable safeguards and retention periods.

03Data we process

User data (we act as controller):

  • identification and account: first name, last name, professional email, identifier;
  • login and security data: authentication logs, IP address, timestamps, browser agent;
  • usage data: campaigns created, operations performed, quota consumption, operation performance and cost metrics;
  • feedback and support: feedback messages, reports of issues;
  • evidence of acceptance of the pilot documents: organisation, name, email address, invitation and activation dates, versions and digital fingerprints of the accepted documents.

Candidate data (we act as processor, on the recruiter's instructions):

  • CVs and application documents imported by the recruiter (PDF, DOCX, TXT);
  • content extracted from those documents and analyses generated by the Service;
  • candidate sheets and reports produced for the recruiter.
We ask recruiters not to import sensitive data (health, opinions, biometrics…), personal data relating to criminal convictions and offences, or data unrelated to the assessment of an application.

04Purposes and legal bases

PurposeLegal basis
Providing the Service and managing pilot accountsContract performance where the user is personally a party to the pilot terms; otherwise, the legitimate interest of INOVAITE and of the pilot organisation in administering and securing access to the Service
Analysing applications and generating outputs for the recruiterLegal basis determined by the controller, as the case may be the Pilot Recruiter or its client; we act as processor or sub-processor, on its documented instructions
Security, logging, abuse prevention, quotasLegitimate interest (protecting the Service and its users)
Technical error monitoringLegitimate interest (Service reliability)
Pilot improvement based on identifiable feedback, then anonymisation or aggregationLegitimate interest (improving IRIS); once effectively anonymised, feedback no longer falls under the GDPR
Retaining evidence of acceptance of the pilot documents (agreements, terms, this policy)Legitimate interest (establishing and enforcing the commitments made)
Compliance with legal obligationsLegal obligation
IRIS makes no automated decision producing legal or similarly significant effects on individuals (GDPR Article 22). IRIS outputs are analysis aids; the recruitment decision always remains with the human recruiter. See the human oversight policy.

05Recipients and processors

Data is neither sold nor rented. It is accessible only to authorised INOVAITE personnel and to our technical processors:

ProcessorRoleLocation
Clever Cloud SASApplication hostingFrance (Paris)
SupabaseDatabase, authentication, file storageIreland (EU); contracting entity Supabase Pte. Ltd. (Singapore), transfers covered by standard contractual clauses
SentryTechnical error monitoring only — minimised data, with no CV, candidate document or report content by defaultGermany (Frankfurt)
Cellar (Clever Cloud)Audit storage and backupsFrance
AI model provider designated in the data processing agreement (DPA), Annex 2AI model analysis processingProcessing possible outside the European Union, in particular in the United States, covered by standard contractual clauses
AI processing: the textual content of job descriptions and candidate documents is transmitted to the AI model provider designated in the data processing agreement (DPA) to produce the analysis requested by the recruiter. This processing may take place outside the European Union, in particular in the United States; it is covered by standard contractual clauses and, where necessary, supplementary measures. The provider is not authorised to use this content to train its models.

06Retention periods

In accordance with our retention and deletion policy:

  • recruiter account: duration of the pilot plus fifteen days;
  • CVs and candidate documents: 30 days after pilot access ends;
  • reports and analyses: 30 days after pilot access ends;
  • campaigns: 30 days after pilot access ends;
  • technical logs: 90 days;
  • audit logs: 12 months;
  • identifiable feedback: 6 months, then anonymised or deleted;
  • evidence of acceptance of the pilot documents: five years after the end of the pilot, the ordinary limitation period under French law (Article 2224 of the Civil Code), then deletion.

At the end of these periods, data is irreversibly deleted or anonymised. After deletion from operational environments, some copies may remain in protected backups that are not used in day-to-day operation, until they are overwritten according to the normal rotation cycle and at the latest ninety days after operational deletion.

07Security

Key measures: encryption in transit (HTTPS), per-user data isolation at database and storage level, named accounts, access control, logging and audit trail, quotas and rate limiting, private storage buckets, EU hosting environment, private code repository, secrets managed outside the code.

In the event of a personal data breach, the applicable role determines who notifies. Where we act as controller (recruiter user data), we notify the CNIL where such notification is required under GDPR Article 33 and, where applicable, inform the individuals concerned under its Article 34. Where we act as processor (candidate data), we inform the relevant recruiter of any breach affecting the data processed on their behalf, as soon as possible and at the latest forty-eight hours after becoming aware of it; we pass on the information available to us and reasonably assist them in assessing the breach and meeting their obligations. Notification to the supervisory authority and information of the individuals concerned then fall to the controller, as the case may be the recruiter or its client, save for any legal obligation directly applicable to INOVAITE.

08Your rights

Depending on the applicable legal basis and under the conditions set out in the GDPR, you have the rights of access, rectification, erasure, restriction and objection, as well as, where it applies, the right to data portability.

Recruiter users: exercise your rights via kamel.irzouni@inovaitesolutions.com.

Candidates: contact first the controller, that is, the organisation that processed your application or on whose behalf it was processed. If you contact us directly, we will forward your request to the relevant recruiter and assist them in responding.

You may lodge a complaint with the CNIL (www.cnil.fr).

09Cookies and trackers

IRIS only uses trackers strictly necessary for the operation of the Service (authentication, session, security). No advertising cookies or third-party analytics trackers are used during the pilot. Should this change, this policy will be updated and your consent collected where required.

10Changes to this policy

This policy may be updated, in particular at the end of the pilot phase. Active users are informed of any substantial change. The applicable version is the one published on the Service.

Document applicable to the closed IRIS pilot.