Introduction
This privacy policy describes how TEEDIA collects, uses, stores and protects personal data, in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act.
It covers two distinct scopes, in which TEEDIA does not act in the same capacity:
- Part A - the teedia.fr marketing website: TEEDIA acts as the data controller for the data of visitors and prospects.
- Part B - the Teedia solution (the SaaS application) and its integrations with third-party services (LinkedIn, Microsoft Teams, etc.): TEEDIA acts as a data processor, on behalf of the client company, which remains the data controller.
Part A - The teedia.fr website
This part concerns data collected while browsing the teedia.fr website (the “Site”).
A.1 Data controller
TEEDIA A company (SARL) registered with the Lyon Trade and Companies Register under number 942 844 291 Registered office: 1 ROUTE DE TREVOUX, 69250 NEUVILLE-SUR-SAONE, France 📧 Contact: contact@teedia.fr
A.2 Data collected
We only collect the data you provide to us voluntarily through:
- The Site’s contact form
The data collected may include:
- First and last name
- Email address
- Phone number (optional)
- Free-text message
A.3 Purposes of processing
The data collected is used solely to:
- Respond to your requests submitted through the contact form
- Establish an initial commercial or informational contact
- Measure website audience (anonymous statistics via Matomo, self-hosted by TEEDIA in France)
- With your consent only: enhanced audience measurement (Google Analytics) and website usability analysis (Microsoft Clarity)
- With your consent only: measure the effectiveness of our campaigns and enable advertising retargeting (LinkedIn Insight Tag)
We do not sell or rent your data to third parties.
A.4 Legal basis
Processing is based on TEEDIA’s legitimate interest in communicating with its prospects, or on your consent when you voluntarily submit your information through a form.
A.5 Recipients of the data
The data is intended exclusively for TEEDIA. It may be accessible to our technical or hosting providers (for example: Clever Cloud, which hosts the website in France), only to the extent necessary for their tasks.
A.6 Retention period
- Data from the contact form is retained for a maximum of 3 years from your last exchange with us.
- Raw audience-measurement data (Matomo) is retained for a maximum of 180 days, then deleted; only aggregated, anonymous statistics are kept beyond that.
- Data collected by Microsoft Clarity (with your consent) is retained in accordance with Microsoft’s policy.
A.7 Cookies and audience measurement
Consent-exempt audience measurement (cookieless)
This website measures its audience with Matomo, a tool that TEEDIA self-hosts in France, configured in accordance with the consent-exemption conditions defined by the French data protection authority (CNIL) for audience measurement:
- no data is transmitted to third parties or cross-referenced with other processing;
- no cookie is set without your consent;
- your IP address is anonymised (the last two octets are removed) and location is limited to city level;
- the statistics produced are aggregated and anonymous, limited solely to audience measurement for TEEDIA’s exclusive use.
You may nonetheless object to any measurement, even anonymous, via the panel below:
Cookies subject to your consent
On your first visit, a banner lets you accept or refuse cookies, category by category, with the same level of simplicity. Your choice (acceptance or refusal) is retained for 6 months and can be changed at any time via the “Manage my cookies” link at the bottom of each page.
| Cookie | Category | Purpose | Duration |
|---|---|---|---|
teedia_consent | Essential | Stores your consent choices | 6 months |
_pk_id | Measurement (Matomo) | Recognises returning visits | 13 months |
_pk_ses | Measurement (Matomo) | Current browsing session | 30 minutes |
_clck | Measurement (Microsoft Clarity) | Clarity identifier | about 1 year |
_clsk | Measurement (Microsoft Clarity) | Groups pages of a single session | about 1 day |
_ga | Measurement (Google Analytics) | Visitor identifier | 13 months |
_ga_* | Measurement (Google Analytics) | GA4 session state | 13 months |
bcookie, lidc, li_gc | Marketing (LinkedIn) | LinkedIn advertising measurement and retargeting | up to 6 months |
UserMatchHistory, AnalyticsSyncHistory | Marketing (LinkedIn) | LinkedIn advertising synchronisation | up to 30 days |
The Marketing category enables, with your consent, the LinkedIn Insight Tag (measuring campaign effectiveness and advertising retargeting on LinkedIn). No advertising cookie is set without your consent.
You can also configure your browser to block cookies.
A.8 Your rights
In accordance with the GDPR, you have the following rights:
- Right of access to your data
- Right to rectification
- Right to erasure (“right to be forgotten”)
- Right to object
- Right to restriction of processing
- Right to data portability
📧 To exercise your rights, contact us at: contact@teedia.fr
We undertake to respond to your request within a maximum of 30 days.
A.9 Security
TEEDIA implements appropriate technical and organisational measures to ensure the security and confidentiality of your personal data.
To learn more, see our security approach and our GDPR and AI Act compliance.
Part B - The Teedia solution and its integrations
This part concerns personal data processed within the Teedia application (the talent-management platform) and through its integrations with third-party services.
B.1 Roles and responsibilities
In connection with the use of the solution:
- The client company (your employer) is the data controller: it determines the purposes and means of processing its employees’ data.
- TEEDIA acts as a data processor within the meaning of Article 28 of the GDPR: we process the data solely on the documented instructions of the client company, under a Data Processing Agreement (DPA).
TEEDIA does not, on its own, determine the purposes of processing HR data and does not use that data for any purpose of its own.
B.2 Categories of data processed
Depending on the modules enabled by the client company, the solution may process:
- Professional identity information (name, job title, department, work contact details)
- Skills and mastery levels
- Appraisal data (records, evaluations)
- Training history and preferences
- Objectives and evaluations
- Responses to surveys
- Professional feedback
- Individual development plans, talent reviews and succession plans
- Data imported from connected third-party services (see Integrations and connectors)
B.3 Purposes
This data is processed, on behalf of the client company, for the purposes of managing appraisals, tracking objectives, managing skills and training, analysing development needs, running internal surveys, internal mobility (talent marketplace) and talent reviews.
B.4 Legal basis
The legal basis is determined by the client company as data controller. For standard HR processing, it generally relies on the performance of the employment contract, compliance with legal obligations and the employer’s legitimate interest. Some processing or integrations additionally rely on the consent of the data subject (see the Integrations section).
B.5 Hosting and data location
The solution’s data is hosted in France, on infrastructure operated by OVHcloud, and is not transferred outside the European Union for hosting and storage purposes.
B.6 Sub-processors and AI providers
TEEDIA may use sub-processors strictly necessary to provide the service. Certain artificial-intelligence features may call on model providers (for example OpenAI, Anthropic, Google, Mistral, Qwen), selectable per feature by the client company, which may also use its own keys (BYOK).
- Your HR data is never used to train an AI model.
- Vector-based matching (skill and training suggestions, etc.) is performed in-house, on Teedia’s French infrastructure.
- The list of sub-processors and the safeguards governing any transfers are provided to the client company under the DPA.
B.7 Retention period
Data is retained for the period defined by the client company as data controller, in accordance with its retention policy and applicable legal obligations. At the end of the contractual relationship, data is returned or deleted according to the client company’s instructions.
B.8 Data subject rights
Employees have the rights of access, rectification, erasure, restriction, objection and portability. These rights are exercised with the client company (data controller), generally through the HR department or the data protection officer. TEEDIA assists the client company in handling these requests and in the operational erasure of data.
B.9 Security
TEEDIA implements appropriate technical and organisational measures, including: secure authentication, role-based access control, strict data isolation between organisations (multi-tenant), encryption, logging and access monitoring. Details of the measures are set out in our security approach and our GDPR and AI Act compliance.
B.10 Integrations and third-party connectors
The Teedia solution can be connected, at the client company’s initiative, to third-party services in order to import or synchronise HR data. Principles common to all integrations:
- The integration is enabled by an administrator of the client company and, where the connection relies on a personal account, authorised by the data subject (consent via OAuth).
- The access tokens issued by the third-party service are encrypted and isolated per organisation (tenant).
- Data is used only for the purpose of the integration, is neither sold nor rented, and is never used to train an AI model.
- The data subject can revoke access at any time (disconnecting the connector in Teedia and/or revoking access on the third-party service); the token is then deleted.
B.11 Contact
For any question regarding data protection within the Teedia solution, or to share the Data Processing Agreement (DPA) with your DPO: 📧 contact@teedia.fr. As an employee, please contact your organisation’s HR department or data protection officer first.
Complaints
If you believe that your rights are not being respected, you may lodge a complaint with the French data protection authority, the CNIL (Commission Nationale de l’Informatique et des Libertés): www.cnil.fr