Your data

Privacy policy

Your trust matters as much as your application. This page explains, in plain words, what data we collect, why, how long we keep it — and the rights you have.

Last updated: 8 July 2026

Who we are

ASTORM GROUP is a consulting and engineering firm with offices in Paris (headquarters), Tunis and Casablanca. We are the data controller for the data collected on this website, within the meaning of Regulation (EU) 2016/679 of 27 April 2016 (the “GDPR”) and the French Data Protection Act of 6 January 1978, as amended.

This page is provided pursuant to the information obligation set out in Articles 13 and 14 of the GDPR. For any question about your data: contact@astorm-group.com.

What data we collect

We only collect what is useful — nothing more.

Why we use it

Each use relies on one of the legal bases provided for in Article 6 of the GDPR:

We never use your data for advertising, and we never sell or rent it to anyone.

Cookies

This site uses a single cookie: a strictly functional language cookie that remembers your preference between French and English for one year.

There are no advertising cookies and no third-party trackers (no Google Analytics, no embedded social networks). Our audience measurement runs server-side, without setting any cookie.

How long we keep your data

The periods below are enforced automatically by our platform, which purges data once it expires.

Who can access your data

Your application data is accessible only to ASTORM GROUP’s recruitment and HR teams, within the scope described above.

It is hosted on our own servers. When we rely on technical providers, they operate under contract and never use your data for their own purposes.

Security and liability

In accordance with Article 32 of the GDPR, we implement appropriate technical and organisational measures to protect your data: encrypted communications (HTTPS), systematic antivirus scanning of uploaded files, strict access control limited to authorised teams, hosting on our own servers and security logging.

However, no information system can be guaranteed to be invulnerable. In the event of fraudulent access to our systems resulting from an external attack (intrusion, malicious code or any other act of cybercrime) committed despite the security measures described above, ASTORM GROUP shall not be held liable, except where fault on its part is proven.

Should such an event occur, we undertake to act in accordance with Articles 33 and 34 of the GDPR: notification of the breach to the supervisory authority within 72 hours and, where the breach is likely to result in a high risk to your rights and freedoms, direct notification of the individuals concerned.

Your rights

In accordance with Articles 15 to 21 of the GDPR, you have the following rights at any time:

To exercise these rights, write to contact@astorm-group.com — we will reply within 30 days. If you believe your rights are not being respected, you may lodge a complaint with the French supervisory authority, the CNIL (cnil.fr).

Changes to this policy

We may update this policy to reflect legal or functional changes to the site. The date of the latest update is shown at the top of this page; in the event of a substantial change, we will say so clearly.