1. Introduction
Tapbuy SAS (hereinafter Qomit) places particular importance on the protection of personal data. Our approach to privacy follows Privacy by Design principles: we proactively integrate data protection into the design of our processes and services rather than treating it as an afterthought.
This policy describes how Qomit collects and processes the data of visitors and users of qomit.com, in compliance with:
- The General Data Protection Regulation (GDPR – EU 2016/679)
- The French Data Protection Act (Loi Informatique et Libertés)
- Other applicable EU and local data protection regulations
Scope: this policy covers processing for which Qomit acts as data controller (corporate site, contact forms, prospecting, marketing, event management). Data processed by the Qomit platform on behalf of its merchant clients is governed by a separate Data Processing Agreement (DPA) and associated Record of Processing Activities (RoPA), under which Qomit acts as data processor.
2. Data Controller
|
|
|
|
Entity |
Tapbuy SAS |
|
Registered office |
6 place de la République Dominicaine, 75017 Paris, France |
|
RCS |
Caen – 948 335 765 |
|
Contact |
hello@qomit.com |
|
Data Protection Officer (DPO) |
Dov Benitah – dpo@qomit.com |
3. Data Collected, Purposes and Legal Bases
Qomit applies the principle of data minimisation: we only collect data that is strictly necessary for the stated purpose.
|
Data collected |
Purpose |
Legal basis (Art. 6 GDPR) |
Retention |
|
Identity, business email, company, role |
Responding to requests, commercial contact, qualification |
Pre-contractual measures (Art. 6.1.b) / Legitimate interest (Art. 6.1.f) |
3 years after last active contact |
|
Email, first name, engagement data |
Marketing communications (newsletter, content, product updates) |
Consent (Art. 6.1.a) |
Until consent is withdrawn + 3 years for proof of consent |
|
Browsing data, pseudonymous identifiers, cookies |
Audience measurement, site improvement, traffic analytics |
Consent (Art. 6.1.a) — via CMP |
13 months (cookies); 25 months (aggregated analytics) |
|
Event registration data (name, email, company, dietary preferences if applicable) |
Managing invitations, attendance, event communications |
Pre-contractual measures (Art. 6.1.b) / Consent (Art. 6.1.a) |
3 years after the event |
|
Business contact details (B2B prospecting) |
Targeted commercial outreach to professionals |
Legitimate interest (Art. 6.1.f) |
3 years after last contact; right to object at any time |
|
Technical data (IP address, user agent, device type, browser) |
Security, fraud prevention, service reliability |
Legitimate interest (Art. 6.1.f) |
12 months |
We do not process sensitive/special-category data (racial origin, political opinions, health data, etc.) through the corporate website.
4. Cookies and Tracking Technologies
When you visit qomit.com, cookies may be set on your device. We distinguish:
|
Category |
Purpose |
Consent required? |
|
Strictly necessary |
Site functionality, security, load balancing |
No (exempt) |
|
Analytics / audience measurement |
Understanding traffic, improving UX |
Yes |
|
Marketing / advertising |
Retargeting, campaign measurement |
Yes |
A Consent Management Platform (CMP) is presented on first visit. You can modify your preferences at any time via the cookie settings link in the site footer.
Cookies are retained for a maximum of 13 months in accordance with CNIL guidelines. No tracking fires before consent is obtained for non-exempt cookies.
5. Data Recipients
Personal data is accessible only to authorised Qomit personnel on a need-to-know basis, following the principle of least privilege and role-based access control (RBAC).
It may be shared with the following categories of processors:
|
Processor |
Purpose |
Location |
|
HubSpot |
CRM, marketing automation, site hosting |
EU & US (SCCs) |
|
Google Cloud Platform (GCP) |
Infrastructure, analytics |
EU (europe-west1, Belgium) |
|
Google Analytics / Tag Manager |
Audience measurement (if consent given) |
EU & US (SCCs) |
Qomit ensures that each processor:
- Offers sufficient guarantees of security and compliance (Art. 28 GDPR)
- Is bound by a written Data Processing Agreement
- Processes data only on Qomit's documented instructions
- Is subject to periodic reassessment based on data sensitivity and criticality
We do not sell personal data. We do not share data for purposes incompatible with those described in this policy.
6. International Data Transfers
Qomit applies an EU-first data residency approach. Where transfers outside the European Economic Area (EEA) are necessary (e.g., HubSpot processing in the United States), they are governed by:
- EU Standard Contractual Clauses (SCCs) approved by the European Commission
- Supplementary technical measures including encryption in transit (TLS 1.2+) and at rest, access controls, and pseudonymisation where feasible
- A documented Transfer Impact Assessment (TIA) evaluating the legal regime of the destination country
You can request details about specific transfer safeguards by contacting the DPO.
7. Data Security
Qomit implements appropriate technical and organisational measures to protect data against unauthorised access, alteration, loss, or disclosure, aligned with ISO/IEC 27001 best practices. These include:
Technical measures:
- Encryption in transit (TLS 1.2+) for all communications and APIs
- Encryption at rest for databases and storage
- Access control via RBAC and multi-factor authentication (MFA) for all critical systems
- Secure secret management (no credentials in source code)
- Centralized logging, monitoring, and alerting for security events
- Regular vulnerability scanning and risk-based patching
Organisational measures:
- Information Security Policy governing all employees, contractors, and third parties
- Mandatory security and privacy awareness training
- Incident response process (detect, contain, eradicate, recover, post-mortem)
- Controlled user lifecycle (provisioning/deprovisioning on onboarding/offboarding)
- Periodic access reviews for critical systems
- Vendor security assessments before onboarding
8. Data Breach Management
In the event of a personal data breach likely to result in a risk to your rights and freedoms, Qomit will:
- Notify the CNIL within 72 hours of becoming aware of the breach (Art. 33 GDPR)
- Inform affected data subjects without undue delay where the breach is likely to result in a high risk (Art. 34 GDPR)
- Document the breach, its effects, and the remedial actions taken
9. Your Rights
Under the GDPR (Articles 15–22), you have the following rights regarding your personal data:
|
Right |
Description |
|
Access |
Obtain confirmation of processing and a copy of your data |
|
Rectification |
Correct inaccurate or incomplete data |
|
Erasure |
Request deletion ("right to be forgotten") where applicable |
|
Restriction |
Limit processing in certain circumstances |
|
Portability |
Receive your data in a structured, machine-readable format |
|
Objection |
Object to processing based on legitimate interest, including profiling |
|
Withdrawal of consent |
Withdraw consent at any time without affecting prior lawfulness |
|
Automated decisions |
Not be subject to decisions based solely on automated processing producing legal effects |
How to exercise your rights:
- Email: dpo@qomit.com or hello@qomit.com
- Response time: within 30 days (extendable by 2 months for complex requests, with notification)
- We may request proof of identity to verify your request
You also have the right to lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés): www.cnil.fr.
10. Data Retention Principles
Qomit retains personal data only for as long as necessary to fulfil the stated purposes, in accordance with:
- Applicable legal obligations (e.g., accounting: 10 years; commercial prospecting: 3 years from last contact)
- CNIL recommendations for specific processing types
- Internal retention schedules reviewed annually
Once the retention period expires, data is deleted, anonymised, or securely archived (for legal obligation purposes only, with restricted access).
11. Links to Third-Party Sites
The site may contain hyperlinks to external websites. Qomit is not responsible for the privacy practices or content of those sites. We encourage you to review their privacy policies before submitting personal data.
12. Changes to This Policy
This policy may be updated to reflect changes in our practices, applicable law, or regulatory guidance. Material changes will be indicated via an updated publication date. The applicable version is always the one published on the site at the date of your visit.
Last updated: 17/07/2026