Contact Us

1. Introduction

Tapbuy SAS (hereinafter Qomit) places particular importance on the protection of personal data. Our approach to privacy follows Privacy by Design principles: we proactively integrate data protection into the design of our processes and services rather than treating it as an afterthought.

This policy describes how Qomit collects and processes the data of visitors and users of qomit.com, in compliance with:

  • The General Data Protection Regulation (GDPR – EU 2016/679)
  • The French Data Protection Act (Loi Informatique et Libertés)
  • Other applicable EU and local data protection regulations

Scope: this policy covers processing for which Qomit acts as data controller (corporate site, contact forms, prospecting, marketing, event management). Data processed by the Qomit platform on behalf of its merchant clients is governed by a separate Data Processing Agreement (DPA) and associated Record of Processing Activities (RoPA), under which Qomit acts as data processor.

 


2. Data Controller

Entity

Tapbuy SAS

Registered office

6 place de la République Dominicaine, 75017 Paris,

France

RCS

Caen – 948 335 765

Contact

hello@qomit.com

Data Protection Officer (DPO)

Dov Benitah – dpo@qomit.com

 


3. Data Collected, Purposes and Legal Bases

Qomit applies the principle of data minimisation: we only collect data that is strictly necessary for the stated purpose.

Data collected

Purpose

Legal basis (Art. 6 GDPR)

Retention

Identity, business email, company, role
(forms)

Responding to requests, commercial contact, qualification

Pre-contractual measures (Art. 6.1.b) / Legitimate interest (Art. 6.1.f)

3 years after last active contact

Email, first name, engagement data
(opens, clicks)

Marketing communications (newsletter, content, product updates)

Consent (Art. 6.1.a)

Until consent is withdrawn + 3 years for proof of consent

Browsing data, pseudonymous identifiers, cookies

Audience measurement, site improvement, traffic analytics

Consent (Art. 6.1.a) — via CMP

13 months (cookies); 25 months (aggregated analytics)

Event registration data (name, email, company, dietary preferences if applicable)

Managing invitations, attendance, event communications

Pre-contractual measures (Art. 6.1.b) / Consent (Art. 6.1.a)

3 years after the event

Business contact details (B2B prospecting)

Targeted commercial outreach to professionals

Legitimate interest (Art. 6.1.f)

3 years after last contact; right to object at any time

Technical data (IP address, user agent, device type, browser)

Security, fraud prevention, service reliability

Legitimate interest (Art. 6.1.f)

12 months

We do not process sensitive/special-category data (racial origin, political opinions, health data, etc.) through the corporate website.

 


4. Cookies and Tracking Technologies

When you visit qomit.com, cookies may be set on your device. We distinguish:

Category

Purpose

Consent required?

Strictly necessary

Site functionality, security, load balancing

No (exempt)

Analytics / audience measurement

Understanding traffic, improving UX

Yes

Marketing / advertising

Retargeting, campaign measurement

Yes

A Consent Management Platform (CMP) is presented on first visit. You can modify your preferences at any time via the cookie settings link in the site footer.

Cookies are retained for a maximum of 13 months in accordance with CNIL guidelines. No tracking fires before consent is obtained for non-exempt cookies.

 


5. Data Recipients

Personal data is accessible only to authorised Qomit personnel on a need-to-know basis, following the principle of least privilege and role-based access control (RBAC).

It may be shared with the following categories of processors:

Processor

Purpose

Location

HubSpot

CRM, marketing automation, site hosting

EU & US (SCCs)

Google Cloud Platform (GCP)

Infrastructure, analytics

EU (europe-west1, Belgium)

Google Analytics / Tag Manager

Audience measurement (if consent given)

EU & US (SCCs)

Qomit ensures that each processor:

  • Offers sufficient guarantees of security and compliance (Art. 28 GDPR)
  • Is bound by a written Data Processing Agreement
  • Processes data only on Qomit's documented instructions
  • Is subject to periodic reassessment based on data sensitivity and criticality

We do not sell personal data. We do not share data for purposes incompatible with those described in this policy.

 


6. International Data Transfers

Qomit applies an EU-first data residency approach. Where transfers outside the European Economic Area (EEA) are necessary (e.g., HubSpot processing in the United States), they are governed by:

  • EU Standard Contractual Clauses (SCCs) approved by the European Commission
  • Supplementary technical measures including encryption in transit (TLS 1.2+) and at rest, access controls, and pseudonymisation where feasible
  • A documented Transfer Impact Assessment (TIA) evaluating the legal regime of the destination country

You can request details about specific transfer safeguards by contacting the DPO.

 


7. Data Security

Qomit implements appropriate technical and organisational measures to protect data against unauthorised access, alteration, loss, or disclosure, aligned with ISO/IEC 27001 best practices. These include:

Technical measures:

  • Encryption in transit (TLS 1.2+) for all communications and APIs
  • Encryption at rest for databases and storage
  • Access control via RBAC and multi-factor authentication (MFA) for all critical systems
  • Secure secret management (no credentials in source code)
  • Centralized logging, monitoring, and alerting for security events
  • Regular vulnerability scanning and risk-based patching

Organisational measures:

  • Information Security Policy governing all employees, contractors, and third parties
  • Mandatory security and privacy awareness training
  • Incident response process (detect, contain, eradicate, recover, post-mortem)
  • Controlled user lifecycle (provisioning/deprovisioning on onboarding/offboarding)
  • Periodic access reviews for critical systems
  • Vendor security assessments before onboarding

 


8. Data Breach Management

In the event of a personal data breach likely to result in a risk to your rights and freedoms, Qomit will:

  1. Notify the CNIL within 72 hours of becoming aware of the breach (Art. 33 GDPR)
  2. Inform affected data subjects without undue delay where the breach is likely to result in a high risk (Art. 34 GDPR)
  3. Document the breach, its effects, and the remedial actions taken

 


9. Your Rights

Under the GDPR (Articles 15–22), you have the following rights regarding your personal data:

Right

Description

Access

Obtain confirmation of processing and a copy of your data

Rectification

Correct inaccurate or incomplete data

Erasure

Request deletion ("right to be forgotten") where applicable

Restriction

Limit processing in certain circumstances

Portability

Receive your data in a structured, machine-readable format

Objection

Object to processing based on legitimate interest, including profiling

Withdrawal of consent

Withdraw consent at any time without affecting prior lawfulness

Automated decisions

Not be subject to decisions based solely on automated processing producing legal effects

How to exercise your rights:

  • Email: dpo@qomit.com or hello@qomit.com
  • Response time: within 30 days (extendable by 2 months for complex requests, with notification)
  • We may request proof of identity to verify your request

You also have the right to lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés): www.cnil.fr.

 


10. Data Retention Principles

Qomit retains personal data only for as long as necessary to fulfil the stated purposes, in accordance with:

  • Applicable legal obligations (e.g., accounting: 10 years; commercial prospecting: 3 years from last contact)
  • CNIL recommendations for specific processing types
  • Internal retention schedules reviewed annually

Once the retention period expires, data is deleted, anonymised, or securely archived (for legal obligation purposes only, with restricted access).

 


11. Links to Third-Party Sites

The site may contain hyperlinks to external websites. Qomit is not responsible for the privacy practices or content of those sites. We encourage you to review their privacy policies before submitting personal data.

 


12. Changes to This Policy

This policy may be updated to reflect changes in our practices, applicable law, or regulatory guidance. Material changes will be indicated via an updated publication date. The applicable version is always the one published on the site at the date of your visit.

Last updated: 17/07/2026