Recomndme Last updated: April 28, 2026

Privacy Policy

We are committed to protecting your personal information and your right to privacy. This notice explains what we collect, why we collect it, and what rights you have.

01

What information do we collect?

Information you provide directly

We collect personal information that you voluntarily provide when you register on our website, express interest in our products or services, participate in activities on the site (such as forums, contests, or giveaways), or contact us.

Personal information may include

Full name Phone number Email address Mailing address Job title Company name Username & password Contact preferences Billing address Payment card details
Information collected automatically

When you visit our website, certain technical information is collected automatically. This does not typically identify you personally but may include:

Automatically collected data

  • Log & usage data — IP address, browser type, device information, pages viewed, features used, timestamps, and error reports.
  • Device data — hardware model, operating system, application identifiers, and ISP or mobile carrier.
  • Location data — approximate or precise location derived from your IP address or device GPS, where you permit it. You may disable location access in your device settings, though some features may be unavailable as a result.

We also collect information through cookies and similar tracking technologies as described in Section 4.

If you register using a social media account, please see Section 5 for details on what we receive from those providers.

All personal information you provide must be accurate and complete. Please notify us of any changes.


02

How do we use your information?

Under GDPR Article 6, every processing activity must rest on a specific legal basis. The table below maps each purpose to its basis and explains our legitimate interest where applicable.

Purpose Legal basis Our legitimate interest (where applicable)
Account creation and log-in (including social login) Contract performance
Delivering and managing the Recomndme service (profile, recommendations, sharing) Contract performance
Processing payments and managing orders Contract performance
Sending transactional and service emails (account notices, policy changes) Contract performance / Legal obligation
Sending marketing and promotional emails Consent (explicit opt-in at registration)
Analytics and product improvement Legitimate interests Understanding how users interact with the service to improve it; data used in aggregated or anonymised form wherever possible
Fraud monitoring and security Legitimate interests Protecting the platform and its users from unauthorized access, abuse, and financial fraud
Customer support and responding to inquiries Legitimate interests / Contract performance Maintaining the quality and reliability of the service
Posting testimonials (with name) Consent
Enabling user-to-user communications Consent
Enforcing our Terms of Use and legal compliance Legal obligation / Legitimate interests Protecting our legal rights and complying with applicable law
Responding to legal requests or court orders Legal obligation
Delivering targeted advertising Consent (via cookie settings)

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms, given the reasonable expectations of users of a professional endorsement platform. You have the right to object to processing based on legitimate interests at any time (see Section 10).


03

Will your information be shared with anyone?

We share personal information only in the circumstances described below. We do not sell your personal data to third parties for their own marketing purposes.

Third-party service providers (data processors)

We engage third-party companies to help us operate and improve the service. Each processor acts only on our documented instructions and is bound by a data processing agreement. Current categories include:

  • Payment processing — to securely handle transactions and billing on our behalf. We do not store full card numbers ourselves.
  • Email delivery — to send transactional and marketing emails. Only your email address and name are shared for this purpose.
  • Analytics — to help us understand usage patterns and improve the service. Data is processed in aggregated or pseudonymised form wherever possible.
  • Cloud hosting & infrastructure — to store and serve the platform. All hosting is within Europe (see Section 6).

You may request a full list of our current processors by contacting us at [email protected].

Legal bases for sharing

  • Your consent — where you have given us specific, informed consent.
  • Legitimate interests — where sharing is reasonably necessary to pursue our legitimate business interests.
  • Contract performance — to fulfill obligations under an agreement with you.
  • Legal obligations — to comply with applicable law, court orders, subpoenas, or governmental requests.
  • Vital interests — to prevent fraud, address safety threats, or protect rights in litigation.

We may also share data in the following specific circumstances:

  • Business transfers — in connection with a merger, acquisition, or sale of company assets.
  • Affiliates — with any subsidiaries or joint venture partners, who are required to honor this policy.
  • Other users — content you post publicly on our platform (your profile, recommendations you receive) may be visible to all users and may be indexed by third parties. This is core to the service and is based on your consent at registration.
If you register via a social network, your contacts on that network may see your name, profile photo, and activity descriptions.

04

Do we use cookies and other tracking technologies?

We use cookies and similar tracking technologies (such as web beacons and pixels) to collect and store information when you use our website. This includes both strictly necessary cookies required for the website to function, as well as other categories of cookies (such as analytics or preference cookies) where you have given your consent.

Our Cookie Policy is incorporated by reference into this Privacy Policy and forms part of it. It provides full details on the cookies we use, their purposes, the third parties involved, and how long they are stored.

You can review and manage your cookie preferences at any time on our Cookie Settings page. Note that disabling certain cookies may affect the functionality of the website.


05

How do we handle your social logins?

Our website allows you to register and log in using third-party social media accounts (such as Facebook or Twitter/X). If you choose to do so, we will receive certain profile information from your social media provider. This may include your name, email address, profile picture, friends list, and any other information you have made public on that platform.

We use this information only for the purposes described in this policy. We do not control how your social media provider uses your data, and we encourage you to review their privacy policies and adjust your privacy settings on those platforms.


06

Is your information transferred internationally?

Our servers and all data are currently stored exclusively within Europe. Your personal information is processed and stored within the European Economic Area (EEA) and is not transferred to countries outside the EEA.

Because we store data in Europe, your information benefits from the protections provided by the General Data Protection Regulation (GDPR) and equivalent European data protection laws. We will notify you if this changes, and take all necessary safeguards before any international transfer of personal data takes place.

We require all third-party data processors we engage to provide equivalent protections under written data processing agreements. Details are available upon request at the contact details in Section 14.


07

How long do we keep your information?

We retain your personal information only for as long as is necessary for the purposes set out in this policy, or as required by applicable law. The table below gives specific retention periods for the main categories of data we hold.

Data category Retention period Reason
Account and profile data Duration of account + 30 days after closure Service delivery; brief grace period for accidental deletion
Recommendations and endorsements Duration of account; or until deleted by the user Core service feature; user-controlled
Payment and billing records 7 years from transaction date French and EU tax and accounting legal requirements
Marketing consent records 3 years from last interaction or opt-in Proof of consent under GDPR
Customer support communications 3 years from resolution Legitimate interest in resolving repeat issues and legal defence
Analytics and usage data 13 months (rolling) CNIL guidance on analytics retention
Security and access logs 12 months Fraud detection and incident investigation
Backup archives Maximum 90 days Business continuity; isolated from active processing

When the applicable retention period expires, we will delete or irreversibly anonymize the data. Where immediate deletion is not technically possible (for example, data in encrypted backup archives), we will securely isolate it from any further processing until deletion is feasible.


08

How do we keep your information safe?

We have implemented appropriate technical and organizational security measures designed to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These include access controls, encryption, and regular security assessments.

However, no method of transmission over the internet or electronic storage is completely secure. While we do our best to protect your data, we cannot guarantee absolute security. You access the website at your own risk, and we encourage you to use a secure internet connection.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the CNIL (Commission Nationale de l'Informatique et des Libertés) within 72 hours of becoming aware of it, as required by GDPR Article 33. Where the breach is likely to result in a high risk to you personally, we will also notify you directly without undue delay, as required by GDPR Article 34.

If you believe your personal information has been compromised, please contact us immediately at [email protected].


09

Do we collect information from minors?

Our website is not directed at individuals under the age of 18. We do not knowingly solicit data from or market to children under 18.

By using our website, you represent that you are at least 18 years old, or that you are the parent or legal guardian of a minor and consent to that minor's use of the website.

If we become aware that we have inadvertently collected personal information from a minor under 18, we will deactivate the account and delete the data promptly. If you have concerns about data we may have collected from a minor, please contact us at [email protected].


10

What are your privacy rights?

Depending on your location, you may have the following rights regarding your personal data:

📋

Right to access

Request a copy of the personal data we hold about you.

✏️

Right to rectification

Request correction of inaccurate or incomplete data.

🗑️

Right to erasure

Request deletion of your personal data in certain circumstances.

⏸️

Right to restriction

Request that we limit how we process your data.

📦

Right to portability

Receive your data in a structured, machine-readable format.

🚫

Right to object

Object to processing based on legitimate interests or for direct marketing.

To exercise any of these rights, please contact us using the details in Section 14. We will respond to your request in accordance with applicable data protection law.

Where we rely on your consent to process personal data, you may withdraw that consent at any time without affecting the lawfulness of prior processing. To withdraw consent for marketing emails, click the unsubscribe link in any email or update your preferences in your account settings. To withdraw consent for non-essential cookies, visit our Cookie Settings page. For any other consent withdrawal, contact us at [email protected].

If you are based in France or the EEA and believe we are unlawfully processing your data, you have the right to lodge a complaint with your national data protection authority. In France, the competent authority is the CNIL (Commission Nationale de l'Informatique et des Libertés) — cnil.fr. A full list of EEA supervisory authorities is available at ec.europa.eu. If you are in Switzerland, please contact the FDPIC at edoeb.admin.ch.

Account settings

To review or change your account information, log in and visit your account settings. To close your account, you may also contact us directly — upon closure we will deactivate and delete your account data, except where retention is required for legal compliance, fraud prevention, or dispute resolution.

Marketing opt-out

You may unsubscribe from marketing emails at any time by clicking the unsubscribe link in any email, or by updating your preferences in your account settings. Note that we may still send you transactional or service-related communications necessary to administer your account.


11

Controls for Do-Not-Track features

Most web browsers, mobile operating systems, and applications include a Do-Not-Track ("DNT") signal. Because no uniform technical standard for recognizing DNT signals has been established, we do not currently respond to DNT signals.

If a legally recognized standard is adopted in the future, we will update this policy accordingly.


12

Do California residents have specific rights?

Yes. California residents have rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), as well as the "Shine the Light" law (Cal. Civ. Code § 1798.83).

Categories of personal information collected (last 12 months)

Category Examples Collected
A. IdentifiersName, email, IP address, account nameYes
B. California Customer RecordsName, contact info, financial informationYes
C. Protected classificationsGender, date of birthYes
D. Commercial informationPurchase history, financial detailsYes
E. Biometric informationFingerprints, voiceprintsNo
F. Internet/network activityBrowsing history, interactions with our siteYes
G. Geolocation dataDevice locationYes
H. Sensory informationImages or recordings related to business activitiesYes
I. Professional informationJob title, work history (e.g., for job applications)Yes
J. Education informationStudent records or directory informationYes
K. InferencesProfiles inferred from the above categoriesYes

Recomndme has not sold or shared personal information with third parties for cross-context behavioral advertising in the preceding 12 months. We may update this practice in the future, and we will notify you of any such change before it takes effect.

California residents have the right to: know what personal data we collect, use, and disclose; request deletion of their personal data; opt out of the sale or sharing of personal data; request correction of inaccurate data; and not face discrimination for exercising these rights.

Under the Shine the Light law, California residents may request, once per calendar year, information about personal data shared with third parties for direct marketing purposes. To make such a request, contact us using the details in Section 14.

Minors under 18 residing in California who have registered accounts may request removal of content they publicly posted. Contact us at [email protected] with your email address and a statement that you reside in California.

To verify your identity when you submit a privacy request, we may ask you to confirm information we already hold on file or contact you through a previously provided communication channel. We will delete any additional verification information as soon as the verification process is complete.

You may designate an authorized agent to submit requests on your behalf. We may deny requests from authorized agents who cannot provide proof of valid authorization.

To submit any California privacy request, contact us at [email protected] or visit your account settings. We will respond to opt-out requests within 15 business days.


13

Do we make updates to this policy?

We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The "Last updated" date at the top of this document indicates when the most recent revision was made.

If we make material changes, we will notify you by prominently posting a notice on our website or by sending you a direct notification, as required by applicable law. We encourage you to review this policy periodically.


14

How can you contact us about this policy?

If you have questions, comments, or concerns about this privacy policy or our data practices, please contact our Data Protection Officer:

DPO Hakim Belanouane
EEA rep. Hakim Belanouane, [email protected]

15

How can you review, update, or delete your data?

Based on the laws of your country, you may have the right to access, correct, or request deletion of the personal information we hold about you.

To exercise these rights, visit your account settings, or contact us directly at [email protected].

We will handle all requests in accordance with applicable data protection law and respond within the timeframes required by law (generally 30 days for GDPR requests, 45 days for CCPA requests).


16

Profiling and automated decision-making

Recomndme is a platform for collecting and sharing professional recommendations. At present, we do not use automated decision-making or algorithmic profiling that produces legal or similarly significant effects on users. Your profile is assembled from information you and your recommenders provide directly — no automated scoring or ranking affects your profile visibility today.

Future features notice. We intend to introduce features that use algorithms to help users and recruiters find better matches based on profile data. Before any such feature is activated, we will update this policy, conduct a Data Protection Impact Assessment (DPIA) as required by GDPR Article 35, and — where the processing constitutes solely automated decision-making with significant effects — provide you with the right to obtain human review, express your point of view, and contest the decision (GDPR Article 22). We will notify you clearly before these features go live.

If and when profiling features are introduced, you will always be able to opt out of automated processing that has a significant effect on you by contacting us at [email protected].