Home DeePsy Pricing Contact

Privacy Policy

Last updated: June 30, 2026

This policy explains how DeePsy processes personal data in connection with its websites, Dashboard, campaigns, questionnaires, IATs, optional artificial-intelligence features and related services.

1. Who processes your data?

DEEPSY, a French simplified joint-stock company registered with the Cannes Trade and Companies Register under number 922 075 494, whose registered office is located at 42 boulevard Montfleury, 06400 Cannes, France, may act depending on the circumstances:

  • as a controller for managing DeePsy’s websites, accounts, prospects, contracts, payments, support, security and legal obligations;
  • as a processor for a Client in relation to campaigns, invitations, Participants, answers, results, comments, documents and replays managed by that Client.

When an employer, recruiter, professional or institution invites you to a campaign, that organisation generally determines the purposes and essential means of processing. It is then your primary contact for campaign-specific information and the exercise of your rights. DeePsy assists it in accordance with its instructions and the GDPR.

Privacy contact: support@deepsy.fr, or by post at the registered office above.

2. Data processed

Depending on your use and the Client’s choices, DeePsy may process:

  • identity and contact data: first name, last name, pseudonym or public alias, email address, telephone number, company, role and language;
  • data provided by companies: information about their directors, members, employees, candidates, clients and other professional contacts whom they are authorised to manage in the Dashboard;
  • legal and commercial identification: legal name, address, country, status, French SIREN or SIRET number, intra-EU VAT number or equivalent identifier, billing details and company-verification information;
  • account and permission data: identifier, encrypted password, organisations, roles, permissions, acceptance of terms and two-factor authentication settings;
  • campaign and recruitment data: role, campaign, invitations, status, notes, comments, attachments and data strictly necessary for professional assessment;
  • test and questionnaire data: answers, selections, free-text responses, reaction times, duration, pauses, progress, test-session events, scores, categories, interpretations and reports;
  • potentially sensitive data: information relating to mental or physical health, disability, accommodations or other special categories where required by the questionnaire and its purpose;
  • LiAna and other AI data: messages, instructions, voluntarily provided files or excerpts, authorised Dashboard context, generated answers, history and feedback;
  • test-session replay data: visual states of the DeePsy test interface only, navigation, clicks, interactions, progress, custom events, timestamps and periods of inactivity required to reconstruct the session;
  • application diagnostics: errors, performance data and sampled technical Dashboard replays, with content masking according to the tool’s configuration;
  • technical and security data: IP address, logs, browser, device, login times, errors, access attempts, tokens and technical identifiers;
  • billing and payment data: billing details, subscription, amounts, invoices, transaction identifiers and partial information provided by the payment provider; DeePsy does not store complete payment-card numbers;
  • communications: contact requests, support conversations, preferences and evidence of consent;
  • interfaces and integrations: API keys, webhooks, resource identifiers and data transferred according to the Client’s configuration.

DeePsy receives this data from you, the Client inviting you, authorised members of that Client, your device, providers required to supply the service or enabled integrations.

3. Purposes and legal bases

Accounts and provision of the Services

DeePsy processes data to authenticate Users, administer organisations, create campaigns, deliver tests, calculate scores, generate and display reports, enable collaboration, provide support and manage subscriptions.

The legal basis is performance of a contract or steps taken before entering into a contract. For Participants invited by a Client, the Client determines the appropriate legal basis and DeePsy processes data on its instructions.

Recruitment and professional assessment

Data may be used to assess professional abilities, organise a selection process and provide decision-support information. The Client must limit information to what is directly and necessarily related to the relevant role, inform candidates in advance about the methods used, ensure result confidentiality and comply with non-discrimination rules.

Depending on the context, the legal basis selected by the Client may be steps taken before entering into a contract or its legitimate interests, balanced against the candidate’s rights. Consent is used only where it is freely given, specific, informed and revocable.

Health, wellbeing and special-category data

Health features may process data covered by Article 9 GDPR. Both an Article 6 legal basis and an Article 9 condition are required. The controller determines these according to the context, for example explicit consent, occupational medicine, preventive care or care delivered by a professional bound by confidentiality, where the relevant legal conditions are met.

Before a test session relying on consent, the Participant must accept the processing presented in the interface. If the Participant refuses, the test cannot begin. This technical step does not release the controller from verifying that consent is an appropriate basis and, where health data is processed, that an Article 9 condition is satisfied.

When a Participant uses a white-label interface and sends a data request directly to the Client, the Client forwards it to DeePsy if assistance is required. DeePsy helps the Client locate, correct, return, delete or irreversibly anonymise the relevant data according to the nature of the request and applicable obligations.

Artificial intelligence

LiAna is an optional Dashboard assistant. It is not part of questionnaires or IATs, does not participate in test-taking and does not alter test scores. The Client may use the Dashboard without using LiAna.

When a User chooses to use it, LiAna may respond to requests, search a DeePsy-hosted knowledge base, help create or translate content, explain or summarise authorised data and assist with certain analyses. Processing is based on performance of the requested service and, for security and controlled service improvement, on the legitimate interests of DeePsy or the Client.

DeePsy does not use data to make final recruitment, health or legally effective decisions on its own. Test results and AI outputs are decision-support materials subject to human verification. The Client must not base a significant decision on exclusively automated processing unless it has an appropriate legal basis and implements the safeguards required by Article 22 GDPR.

Test-session replays

A replay is automatically created during each test session to verify the conditions in which the test was completed, its progress, response times, interruptions and possible anomalies. It records activity only within the DeePsy test interface and does not access the camera, microphone, other browser tabs, other applications or content outside that interface. The Participant is informed about the processing before taking the test and replay access is restricted to authorised persons.

Security and abuse prevention

Logs and technical data are used to secure accounts, prevent fraud, detect incidents, ensure continuity and establish, exercise or defend legal claims. This processing is based on DeePsy’s legitimate interests and compliance with its legal security obligations.

In production, DeePsy uses Sentry to diagnose Dashboard errors and performance. Technical replays are sampled for some sessions and when errors occur. They are separate from automatic test-session replays and are used only for service diagnostics and security.

Payments, accounting and legal obligations

Billing data is processed to perform the contract, receive payments, manage unpaid amounts and comply with accounting, tax and judicial obligations.

Communications

Contact and support requests are processed to respond to you, on the basis of pre-contractual measures or legitimate interests. Electronic marketing communications rely on consent where required; you may unsubscribe at any time.

Statistics and improvement

DeePsy may produce aggregated statistics and use effectively anonymised data to measure, secure and improve its Services. An encrypted identity or an identity replaced with an alias remains personal data for as long as DeePsy or the Client can reasonably restore a link to the person.

4. AI: data transfers and precautions

In production, DeePsy uses Mistral AI and OVHcloud AI Endpoints to process requests from Dashboard AI features. Only data useful for the relevant task should be transferred. This may include the message, necessary history, document excerpts, test structures or results the User is authorised to access.

DeePsy applies data-minimisation and identity-masking mechanisms where the feature permits. However, an alias, stable identifier, free-text entry or combination of information may enable re-identification. Users must therefore avoid entering unnecessary names, contact details, health data or confidential information in their requests.

LiAna’s documentary search relies on search and retrieval-augmented generation tools hosted and administered by DeePsy. Conversations may remain in the account history until deleted or for the applicable retention period.

OVHcloud states that data submitted to AI Endpoints is neither stored beyond what is required for billing nor used to train or improve its models. Mistral AI’s commercial terms exclude model training on Client data and outputs for the relevant commercial products, subject to the exceptions stated in those terms, including certain voluntary feedback, flagged content or experimental models. DeePsy does not voluntarily use Client data to train these providers’ general-purpose models and does not enable a training option for that purpose.

5. “Anonymised Participant” mode

A campaign may be configured in anonymisation mode. A public alias then replaces the first and last names in the relevant views, reports, exports, webhooks and notifications. This feature masks identity from Client members viewing the results.

Where DeePsy retains encrypted identity data or a usable technical correspondence to operate an invitation or Service, the operation legally remains pseudonymisation until that correspondence is irreversibly destroyed. Where no usable correspondence remains and the person can no longer reasonably be re-identified, the data is considered anonymous. Client members do not receive the identity through the views provided in anonymisation mode.

6. Recipients and providers

Data is accessible on a need-to-know basis to authorised DeePsy teams, authorised Client members and the Participant where supported by the relevant feature.

DeePsy notably uses the following categories of providers:

  • OVHcloud: hosting, infrastructure, object storage in France and AI services depending on configuration;
  • Mollie B.V.: payments and transaction management;
  • Mailjet: transactional emails, invitations and communications;
  • Mistral AI: Dashboard AI models and services;
  • OVHcloud AI Endpoints: Dashboard AI models and services;
  • Sentry: production Dashboard error monitoring, performance monitoring and technical replays;
  • Google Analytics: showcase website audience measurement, only after consent where required;
  • technical providers and professional advisers: maintenance, security, legal or accounting support, strictly as required.

Data may also be disclosed to a public authority, court or third party where required by law, to protect legal rights or as part of a corporate restructuring subject to appropriate safeguards.

The Client may enable its own recipients, API keys, webhooks or integrations. It is responsible for this configuration and must inform you about any additional recipients.

7. Location of processing

DeePsy’s main infrastructure, databases and object storage are located in France. Production services used for sending emails and processing AI requests are configured to process data in Europe. Mailjet states in particular that it stores personal data exclusively in data centres located in the European Union.

DeePsy does not intentionally transmit campaign content, answers, results, replays or LiAna conversations to a processing region outside the European Economic Area. Optional audience-measurement services on the showcase website remain subject to the User’s consent choices and the applicable safeguards of their provider. Google Analytics does not receive Dashboard content, Client test data or identifiable candidate records from DeePsy.

8. Retention periods

For campaigns administered by a Client, that Client selects the retention period for the paid data for which it is responsible, within the limits of its agreement and the law. DeePsy does not unilaterally delete those results while their retention remains requested and lawful. In practice:

  • account and service data: for the duration of the contractual relationship, followed by the period required to manage complaints and applicable limitation periods;
  • campaign data, answers, results and Participant files: for the period selected by the Client, provided that it remains justified by the purpose and complies with legal obligations;
  • applications retained for a candidate pool: generally no more than two years after the last contact, under the Client’s responsibility and provided the candidate has been informed;
  • LiAna conversations: while the paid Client account remains active to preserve the history requested by the User; the User may delete a conversation or their entire history from the Dashboard at any time; upon contract termination, conversations are deleted or returned according to the Client’s instructions, contractual terms and any applicable legal obligations;
  • DeePsy test-session replays: 7 days for the free plan or 365 days for a subscribed company from the end of recording, followed by a 30-day technical grace period before permanent deletion;
  • Sentry events and technical replays: 90 days;
  • contact and support requests: for the time required to process the request, followed by the period necessary for follow-up and the defence of legal rights;
  • invoices and accounting records: 10 years where required by French law;
  • security logs: for a period proportionate to the risk and investigation needs;
  • showcase website cookies and trackers: according to their purpose and, where consent is required, within the limits recommended or imposed by the competent authority.

Where a Participant uses a Service directly without a campaign administered by a Client, DeePsy retains the data for the maximum period compatible with the stated purpose, service relationship and applicable legal periods, then irreversibly anonymises it when retaining it in identifiable form is no longer justified.

Logical deletion may occur before final removal from backups or data subject to a legal retention obligation. Effectively anonymised data is no longer personal data and may be retained for statistical or scientific purposes.

9. Cookies and browser storage

The showcase website uses local storage to remember cookie choices and may load Google Analytics for audience measurement after analytics cookies have been accepted.

The Dashboard does not set advertising or audience-measurement cookies. It uses a strictly functional authentication cookie and local or session browser storage to maintain login, security, interface preferences and multi-tab operation. Sentry is a separate diagnostic tool and is not a cookie.

Non-essential trackers are used only after consent where required. You may withdraw consent as easily as you gave it. Refusing optional trackers does not prevent access to essential features, although some preferences may not be remembered.

10. Security and confidentiality

DeePsy implements measures appropriate to the risk, including access controls, available strong authentication, encrypted communications, logging, backups, organisation-level segregation, data minimisation and incident-management procedures.

No system can provide absolute security. In the event of a breach likely to create a risk, DeePsy notifies the competent authority under the legally applicable conditions and assists the Client with its own obligations. Affected persons are informed where the breach is likely to result in a high risk.

11. Your rights

Subject to the conditions established by the GDPR, you have the following rights:

  • access to your data and a copy of it;
  • correction of inaccurate or incomplete data;
  • erasure;
  • restriction of processing;
  • objection to processing based on legitimate interests and objection to direct marketing at any time;
  • portability of data you provided where processing is automated and based on consent or a contract;
  • withdrawal of consent at any time, without affecting the lawfulness of earlier processing;
  • not to be subject to a decision based exclusively on automated processing that produces legal or similarly significant effects, except where a legal exception applies, and to obtain human intervention;
  • to provide instructions governing your data after your death in accordance with French law;
  • to lodge a complaint with the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr.

For a campaign administered by an employer, recruiter or institution, first send your request to that organisation. You may also contact support@deepsy.fr, specifying the relevant Client and campaign. DeePsy may request information strictly necessary to verify your identity; an identity document is requested only where there is reasonable doubt.

Where the right to erasure applies, DeePsy may respond by deleting data or by effectively and irreversibly anonymising it so that reasonable re-identification is no longer possible. A correction request may be completed directly through available features, by the Client responsible for the campaign or with DeePsy’s assistance.

A response is generally provided within one month. This period may be extended by two months for complex or numerous requests, after the affected person has been informed.

12. Specific Client obligations

A Client inviting Participants must in particular:

  • inform persons, under its own identity and including under a white label, about the applicable purposes, legal bases, recipient categories and retention periods;
  • limit collected data to what is necessary;
  • select relevant tests and persons qualified to interpret the results;
  • appropriately manage health and other special-category data;
  • inform candidates in advance about the assessment methods used and, only where applicable, any use of AI liable to significantly influence a decision;
  • implement the required safeguards where a decision is exclusively automated and produces legal or similarly significant effects; this concerns the final decision and does not require a human supervisor to be present while an online test is being taken;
  • preserve result confidentiality and limit access to persons who need it;
  • keep data accurate, handle data-subject requests and notify DeePsy where assistance is required;
  • define and apply a lawful retention period, then request deletion or irreversible anonymisation of data that is no longer needed;
  • promptly notify DeePsy about unauthorised access, loss, disclosure or a security incident concerning the Services;
  • assess whether a data-protection impact assessment is required, particularly for systematic assessment, large-scale sensitive data, monitoring or new technology;
  • where it uses an AI feature in employment, worker management or access to employment, comply with the legal obligations applicable to that specific use.

13. Changes to this policy

DeePsy may amend this policy to reflect developments in the Services, providers or applicable law. The last-updated date appears at the top of the document. Where a change is material, affected persons will be informed by an appropriate means and new consent will be obtained where required.

14. Related documents

Use of DeePsy Services is also subject to the Terms of Service and legal notice.

This Privacy Policy was originally drafted in French. This English translation is provided for information and convenience only. In the event of any discrepancy or conflict, the French version prevails, subject to any mandatory law to the contrary.