GDPR

Privacy policy

How Koraisoft collects, uses and protects your personal data.

Data controller

In the course of its business, Koraisoft acts primarily as a technical subcontractor, meaning it does not host or directly process its end customers' data, unless otherwise specified in a specific contract.

Data collected

Koraisoft only collects data strictly necessary for communication with users and partners:

• Name, surname, company, position

• Professional email address

• Technical information exchanged during projects

No sensitive data (health, origin, religion, etc.) is collected.

Purpose of processing

The data collected is used exclusively to:

• Respond to contact or support requests

• Prepare quotes, invoices or contracts

• Monitor ongoing projects

• Improve the tools and services offered

Data is never resold, transferred or used for advertising purposes.

Retention period

Data is retained for a maximum of 5 years after the last contact or end of the contractual relationship.

After this period, data is deleted or anonymized.

Data hosting

Data is hosted exclusively in Europe, in compliance with GDPR requirements.

Host: Infomaniak (Switzerland).

Rights of data subjects

In accordance with GDPR (General Data Protection Regulation), any data subject has the following rights:

• Right to access: obtain a copy of your personal data

• Right to rectification: correct inaccurate or incomplete data

• Right to erasure (right to be forgotten): request deletion of your data

• Right to restriction of processing: limit the use of your data

• Right to object: object to the processing of your data

• Right to data portability: retrieve your data in a structured format

• Right to withdraw consent at any time

• Right to lodge a complaint with the CNIL (French Data Protection Authority)

To exercise these rights:

Koraisoft commits to responding to any request within a maximum of 30 days. Proof of identity may be requested to verify your identity.

Security

Koraisoft implements appropriate technical and organizational measures:

• Restricted access to technical environments

• Encrypted communications (HTTPS, SSH, VPN)

• Encrypted backups and access controls

Transfers outside EU

No transfer of personal data outside the European Union is made, except for legal obligation or explicit client agreement.