Legal Center

Privacy policy

How BELOCAL processes personal data in connection with the OPERIANCE website and service.

Last updated : 22 August 2026

These documents describe the framework applicable to operiance.com and the OPERIANCE service. They may evolve; the version published online is the applicable version. The English version is provided for ease of understanding. Unless a specific contractual agreement states otherwise, the French version prevails in the event of any discrepancy.

Data controller

For its own processing activities (commercial relationship, account management, billing, security, abuse prevention, legal obligations), the controller is:

Company
BELOCAL SAS
Address
60 rue François Ier, 75008 Paris, France
Contact
hello@operiance.com

Where BELOCAL processes data on behalf of a client organisation as part of its business processes, that organisation is generally the controller and BELOCAL acts as processor, within the scope defined by the applicable data processing agreement (DPA).

Data that may be processed

Depending on how the website and the service are used, the following categories may be processed:

  • Identity and professional contact details
  • Account and organisation data
  • Contact or demo requests
  • Contractual and billing data
  • Candidate and profile data where the service is used for that purpose
  • CVs and professional documents
  • Information related to assignments and requirements
  • Qualification responses and positioning information
  • Generated documents and deliverables
  • Technical and connection data
  • Necessary security and usage logs

Purposes

  • Providing and operating OPERIANCE
  • Managing accounts and organisations
  • Performing contracts and responding to requests
  • Providing support and issuing invoices
  • Securing the platform and preventing abuse
  • Complying with applicable legal obligations
  • Improving the technical operation of the service according to applicable roles

Legal bases

  • Performance of a contract or pre-contractual measures
  • Legitimate interest (security, abuse prevention, commercial relationship management, technical improvement)
  • Legal obligation
  • Consent, only where it is genuinely required

Recipients and providers

  • Authorised BELOCAL personnel
  • Authorised users of the client organisation
  • Providers necessary to operate the service
  • Legally competent authorities where required by law

Providers are involved by category: cloud hosting and infrastructure, artificial intelligence model providers, email delivery, and technical services necessary to operate the service.

Additional information about providers can be shared within a contractual or due diligence framework.

International transfers

The primary infrastructure is located in the European Union. Some providers may nevertheless involve processing outside the European Economic Area.

Where such transfers occur, the applicable legal mechanisms (in particular standard contractual clauses or an adequacy decision) are used where required.

Retention periods

Retention periods depend on the nature of the data, the contractual context, legal obligations and applicable internal rules.

  • Unconverted prospects: retention of up to three years from the last relevant commercial contact, subject to applicable regulations.
  • Active clients: retention for as long as needed for the contractual relationship, then according to the applicable end-of-relationship periods and mechanisms.
  • Billing data and accounting obligations: retention for the legally required periods.

Artificial intelligence

Certain processing activities use automated systems and artificial intelligence models to analyse, structure, match, summarise, flag information to be confirmed and enrich available information.

The purpose is to assist the business process, not to artificially create experience or skills. No absolute accuracy or completeness is guaranteed and important elements must be verified.

Enrich the information. Never invent it.

Security

Reasonable technical and organisational measures are implemented: access control, strong authentication for administrative access, encryption in transit, logging and monitoring.

As no measure can guarantee absolute security, these measures constitute a best-efforts obligation and evolve with the state of the art.

Data subject rights

Where applicable, data subjects have the following rights:

  • Access
  • Rectification
  • Erasure
  • Restriction
  • Objection
  • Portability
  • Withdrawal of consent where processing is based on consent
  • Lodging a complaint with the CNIL (French data protection authority)

These rights can be exercised at hello@operiance.com. Reasonable identity verification may be requested where necessary.

Where data is processed on behalf of a client organisation, the request may be redirected to that organisation as controller.

Cookies and trackers

  • Trackers strictly necessary for the operation of the website and service
  • Storage of the selected language

No advertising trackers are used and no consent-based analytics are currently deployed. Should such technologies be added, they would only be triggered after the applicable consent has been obtained.

Version
1.0
Effective date
22 August 2026
Last updated
22 August 2026