Data protection

Privacy Policy

How HORA INTERIM collects, uses, protects and retains your personal data, in accordance with the GDPR (Regulation (EU) 2016/679) and the French Data Protection Act.

Last updated: August 1, 2026

1. Introduction and data controller

HORA INTERIM attaches essential importance to protecting the personal data of candidates and visitors to its website. This privacy policy explains, in clear language, what data is collected, why, how it is protected, and what rights you can exercise.

It is drawn up in accordance with Regulation (EU) 2016/679 of 27 April 2016 ("GDPR") and amended French law No. 78-17 of 6 January 1978 ("Data Protection Act").

HORA INTERIM acts as the data controller for all data collected via this website, in particular through the application form, the contact form and the documents submitted.

Data controller contact details

  • Name: HORA INTERIM
  • Address: 10 Rue de la Paix, 75002 Paris, France
  • Phone:
  • Email:
  • Opening hours: Monday to Friday, 9:00 AM – 12:30 PM and 2:00 PM – 6:00 PM

2. Data collected

We only collect the data necessary to process your application and to ensure the secure operation of the website (data minimization principle).

Personal information

  • Last name
  • First name
  • Gender
  • Date of birth
  • Nationality
  • Address
  • Country of residence
  • Phone number
  • Email address

Professional information

  • Curriculum vitae (CV)
  • Qualifications and diplomas
  • Work experience
  • Desired occupation and destination
  • Education level and training institution
  • Languages spoken

Documents submitted

  • Passport or national identity card
  • Proof of address
  • Diplomas and training certificates
  • Certificates that may be requested depending on the position (medical certificate, criminal record, professional qualifications)
  • Proof of payment of the file-processing fee

Technical information

  • IP address
  • Cookies and session identifiers
  • Browser type and version
  • Device type and operating system
  • Connection and activity logs
  • Security data (login attempts, document access logs)

3. Purposes of processing

Your data is used exclusively for the following purposes:

  • processing and reviewing applications submitted on the website;
  • verifying the authenticity and consistency of supporting documents provided;
  • contacting candidates about their file (email, phone);
  • managing administrative files and monitoring their status;
  • forwarding applications to partner employers when necessary for recruitment;
  • complying with applicable legal, accounting and regulatory obligations;
  • ensuring the security of the website, its access points and hosted documents;
  • preventing, detecting and addressing fraud and misuse.

No decision producing legal effects is made solely on the basis of automated processing regarding you: applications are reviewed by our human teams.

4. Legal bases for processing

Each processing activity relies on a legal basis under Article 6 of the GDPR:

ProcessingLegal basis
Submission and review of the applicationPerformance of pre-contractual measures taken at your request (Art. 6.1.b)
Health documents and sensitive dataExplicit consent (Art. 6.1.a and Art. 9.2.a)
Transmission to partner employersCandidate's consent (Art. 6.1.a)
Non-essential cookies and statisticsConsent (Art. 6.1.a)
Accounting retention and legal obligationsLegal obligation (Art. 6.1.c)
Website security, fraud prevention, loggingLegitimate interest (Art. 6.1.f)

Where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before its withdrawal.

5. Data recipients

Your data is only accessible to strictly authorized persons:

  • authorized HORA INTERIM recruiters, within the scope of their duties;
  • platform administrators, for technical management and file follow-up;
  • partner companies, only when your profile is shortlisted for a position;
  • technical service providers (processors within the meaning of Article 28 of the GDPR) involved in hosting, maintenance, document storage or email delivery.

6. Retention period

Data is retained only for as long as strictly necessary for the purposes pursued, after which it is deleted or securely archived.

Data categoryRetention period
Unsuccessful application2 years from the last contact (CNIL recommendation), unless earlier deletion is requested
Application under reviewDuration of file processing, then application of the periods above
Identity documents and supporting documentsDuration of file processing, then deletion, unless otherwise required by law
Proof of payment and accounting records10 years (accounting and tax obligations)
Health data (where applicable)Duration strictly necessary for the purpose, then deletion
Connection and security logs12 months maximum
Cookies13 months maximum from deposit
Proof of consentDuration of the relevant processing, then 3 years for evidentiary purposes

7. Data security

HORA INTERIM implements appropriate technical and organizational measures to ensure a level of security adapted to the risks (Article 32 of the GDPR):

  • secure hosting with professional providers located within the European Union;
  • encryption of communications via HTTPS/TLS protocol;
  • role-based access control (administrator, recruiter, read-only);
  • authentication of administrator accounts and strong password policy;
  • logging of access to sensitive documents and administrative actions;
  • regular database backups;
  • storage of documents in a private area not publicly accessible;
  • access to files only via time-limited signed temporary links.

In the event of a data breach likely to result in a high risk to your rights and freedoms, you will be informed as soon as possible, in accordance with Article 34 of the GDPR, and the supervisory authority will be notified within 72 hours.

8. Your rights

In accordance with Articles 15 to 22 of the GDPR, you have the following rights:

  • Right of access: obtain confirmation that your data is being processed and receive a copy of it.
  • Right to rectification: have inaccurate or incomplete data corrected.
  • Right to erasure: request deletion of your data, subject to our legal obligations.
  • Right to restriction: request the temporary suspension of processing.
  • Right to object: object to processing based on legitimate interest.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to withdraw your consent at any time, for processing that depends on it.

9. Cookies

A cookie is a small file placed on your device when you browse the website. We use the following categories:

CategoryPurposeConsent
Essential cookiesWebsite operation, session, application formNot required
Security cookiesProtection against fraud and unauthorized accessNot required
Preference cookiesRemembering your display and language choicesRequired
Statistics cookiesAudience measurement and website improvementRequired

You may withdraw your consent or change your choices at any time from your browser settings, which also allow you to block or delete cookies already stored. Refusing non-essential cookies does not prevent access to the website or submission of an application.

10. Services and technical providers used

The website relies on the following providers, each operating within a limited scope governed by a data processing agreement:

ServiceRole
SupabaseDatabase, administrator account authentication and secure document storage
ResendSending transactional emails (acknowledgments, status notifications)
Google MapsDisplaying the agency's location map on the Contact page
OVHDomain name registration and related services
LovableHosting and delivery of the web application

Other services may be added as needed, in particular an audience measurement tool (Google Analytics) or an online payment solution (Stripe). Such services are only activated when actually necessary; this policy will be updated accordingly and, where applicable, your consent will be obtained beforehand.

11. International data transfers

Our data is primarily hosted within the European Union. However, certain technical providers may process data outside the European Economic Area.

In such cases, these transfers are governed by the mechanisms set out in Chapter V of the GDPR: an adequacy decision of the European Commission, standard contractual clauses (SCCs), or, failing that, appropriate safeguards accompanied by supplementary measures (encryption, minimization, access control).

Furthermore, where your application concerns a position located outside the European Union (for example in Canada), the transmission of your file to the relevant partner employer constitutes a transfer necessary for the performance of pre-contractual measures taken at your request, carried out with your consent.

12. Complaints

If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the competent data protection authority.

In France, this is the Commission Nationale de l'Informatique et des Libertés (CNIL) — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.

If you reside in another European Union member state, you may contact the supervisory authority of your habitual place of residence or place of work.

13. Policy updates

This privacy policy may be amended at any time to reflect legal, regulatory, judicial or technical developments, as well as changes to the website and our services.

In the event of a material change, candidates with an active file will be notified by email. We invite you to check this page regularly; the date of the last update appears at the top of the document.

A question about your data?

Contact our data protection team at or by phone at .