Privacy Policy (GDPR)
BCIT Formation places great importance on protecting your personal data. This policy describes how your data is collected, used, retained and protected, as well as the rights you have.
1. Data controller
The controller of personal data processing is BCIT Formation, a simplified joint-stock company (SAS) with share capital of 1,000 euros, whose registered office is located at 33 rue des Charmes, 16110 Pranzac (Charente), registered with the Angoulême Trade and Companies Register under number B 912 443 876 (SIREN 912 443 876, SIRET 912 443 876 00038). For any question relating to the processing of your data, you can contact us at contact@bcit.fr.
2. Data collected
Depending on the context of your browsing and your relationship with BCIT, we may collect the following categories of data:
- Identification data: last name, first name, job title, company.
- Contact data: email address, phone number, postal address.
- Data collected via the forms contact and appointment booking: contact details, message, desired time slot.
- Newsletter subscription data: email address.
- Training-related data: needs, prerequisites, educational follow-up, certificates.
- Data related to commercial transactions and billing.
- Browsing data: IP address, technical connection data and cookies (see our cookie management policy).
3. Purposes
Your data is processed for the following purposes:
- Managing contact and appointment requests.
- Organising, delivering and monitoring training and consulting services.
- Managing the commercial relationship, transactions and billing.
- Compliance with our legal and regulatory obligations (in particular accounting obligations and those related to our activity as a training organisation).
- Sending information and communications (newsletter), subject to your consent where applicable.
- Proper operation and security of the website.
4. Legal bases
Depending on the case, processing is based on:
- Performance of a contract or pre-contractual measures (management of services).
- Compliance with a legal obligation (accounting and training obligations).
- Our legitimate interest (improving our services, website security).
- Your consent (in particular for the newsletter).
5. Recipients and processors
Your data is intended for BCIT's authorised internal departments. Your data is not sold. It may be disclosed to processors (hosting provider, customer relationship management tools, emailing, maintenance and IT service providers) acting on behalf of BCIT and according to its instructions, as well as to trainers, certification bodies, funders and public bodies where required by regulation. BCIT ensures that its processors provide sufficient guarantees with regard to the GDPR.
6. Transfers outside the European Union
Your data is not transferred outside the European Union. The website is hosted by Odoo SA, Chaussée de Namur 40, 1367 Ramillies, Belgium (European Union), within the European Union.
7. Retention periods and data lifecycle
For the same processing operation, your personal data follows a “lifecycle” that may include three successive phases:
- Retention in the active database: the period necessary to achieve the purpose that justified the collection. The data remains easily accessible to BCIT operational teams responsible for the processing (e.g. handling a contact request, monitoring an ongoing training course).
- Intermediate archiving: the data is no longer used to achieve the initial purpose (“closed file”) but is retained because it still has administrative value (management of possible litigation) or to meet a legal obligation. It is then isolated from the active database (logical separation through restricted permissions) and only specifically authorised persons may consult it, on a one-off and justified basis.
- Permanent archiving: a non-systematic phase, implemented only when information has value justifying long-term retention or when a legal text requires it. Otherwise, data is deleted or anonymised at the end of the lifecycle.
The need for each phase is assessed for each processing operation. The applicable period is set by regulation where a legal text provides for it; otherwise, it is determined by BCIT according to the purpose of the processing, based on the practical guide and retention-period references published by the CNIL. As an indication:
- Prospects and contact requests: 3 years from the last unanswered contact.
- Clients (commercial relationship): throughout the relationship, then in intermediate archiving for 3 years from the last interaction.
- Accounting documents and supporting records (invoices): 10 years (Article L123-22 of the French Commercial Code).
- Payslips and HR data of employees: 5 years (Article L3243-4 of the French Labour Code).
- Data of unsuccessful job applicants: a maximum of 2 years after the last contact, unless erasure is requested.
- Training files and certificates: retained in accordance with our regulatory obligations, then archived.
- Newsletter subscription: until withdrawal of your consent (unsubscribe).
- Cookies and trackers: maximum 13 months (see our cookie management policy).
The same data may be used for separate processing operations subject to different retention periods: archiving or deleting it in one processing operation does not prevent its continued use in another. At the end of the applicable periods, your data is deleted or anonymised.
8. Security
BCIT implements appropriate technical and organisational measures to protect your data against unauthorised destruction, loss, alteration, disclosure or access, in line with its cybersecurity expertise.
9. Your rights
In accordance with the GDPR, you have the following rights over your personal data:
- Right of access: obtain confirmation that data concerning you is being processed and obtain a copy of it.
- Right to rectification: have inaccurate or incomplete data corrected.
- Right to erasure: request deletion of your data under the conditions provided for by law.
- Right to object: object to the processing of your data on legitimate grounds or for direct marketing purposes.
- Right to data portability: receive the data you provided in a structured, machine-readable format.
- Right to restriction: request the temporary suspension of processing of your data.
10. Exercising rights and contacting the DPO
You can exercise your rights by contacting BCIT via our page contact or by writing to our data protection officer (DPO), Corentin BARDIN, at the address dpo@bcit.fr. Proof of identity may be requested. BCIT undertakes to respond within one month, extendable depending on the complexity of the request.
11. Cookies
Our website uses only cookies that are strictly necessary for its operation and security. To learn more about their nature and purpose, please consult our cookie management policy.
• Complaint to the CNIL (
If, after contacting us, you believe that your rights are not being respected, you may lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or via its website www.cnil.fr.
10. Policy update
This policy may be amended at any time to take account of legal, regulatory or technical developments. We invite you to consult it regularly. The date of the last update appears below.
Privacy Policy (GDPR)
BCIT Formation places great importance on protecting your personal data. This policy describes how your data is collected, used, retained and protected, as well as the rights you have.
1. Data controller
The controller of personal data processing is BCIT Formation, a simplified joint-stock company (SAS) with share capital of 1,000 euros, whose registered office is located at 33 rue des Charmes, 16110 Pranzac (Charente), registered with the Angoulême Trade and Companies Register under number B 912 443 876 (SIREN 912 443 876, SIRET 912 443 876 00038). For any question relating to the processing of your data, you can contact us at contact@bcit.fr.
2. Data collected
Depending on the context of your browsing and your relationship with BCIT, we may collect the following categories of data:
- Identification data: last name, first name, job title, company.
- Contact data: email address, phone number, postal address.
- Data collected via the forms contact and appointment booking: contact details, message, desired time slot.
- Newsletter subscription data: email address.
- Training-related data: needs, prerequisites, educational follow-up, certificates.
- Data related to commercial transactions and billing.
- Browsing data: IP address, technical connection data and cookies (see our cookie management policy).
3. Purposes
Your data is processed for the following purposes:
- Managing contact and appointment requests.
- Organising, delivering and monitoring training and consulting services.
- Managing the commercial relationship, transactions and billing.
- Compliance with our legal and regulatory obligations (in particular accounting obligations and those related to our activity as a training organisation).
- Sending information and communications (newsletter), subject to your consent where applicable.
- Proper operation and security of the website.
4. Legal bases
Depending on the case, processing is based on:
- Performance of a contract or pre-contractual measures (management of services).
- Compliance with a legal obligation (accounting and training obligations).
- Our legitimate interest (improving our services, website security).
- Your consent (in particular for the newsletter).
5. Recipients and processors
Your data is intended for BCIT's authorised internal departments. Your data is not sold. It may be disclosed to processors (hosting provider, customer relationship management tools, emailing, maintenance and IT service providers) acting on behalf of BCIT and according to its instructions, as well as to trainers, certification bodies, funders and public bodies where required by regulation. BCIT ensures that its processors provide sufficient guarantees with regard to the GDPR.
6. Transfers outside the European Union
Your data is not transferred outside the European Union. The website is hosted by Odoo SA, Chaussée de Namur 40, 1367 Ramillies, Belgium (European Union), within the European Union.
7. Retention periods and data lifecycle
For the same processing operation, your personal data follows a “lifecycle” that may include three successive phases:
- Retention in the active database: the period necessary to achieve the purpose that justified the collection. The data remains easily accessible to BCIT operational teams responsible for the processing (e.g. handling a contact request, monitoring an ongoing training course).
- Intermediate archiving: the data is no longer used to achieve the initial purpose (“closed file”) but is retained because it still has administrative value (management of possible litigation) or to meet a legal obligation. It is then isolated from the active database (logical separation through restricted permissions) and only specifically authorised persons may consult it, on a one-off and justified basis.
- Permanent archiving: a non-systematic phase, implemented only when information has value justifying long-term retention or when a legal text requires it. Otherwise, data is deleted or anonymised at the end of the lifecycle.
The need for each phase is assessed for each processing operation. The applicable period is set by regulation where a legal text provides for it; otherwise, it is determined by BCIT according to the purpose of the processing, based on the practical guide and retention-period references published by the CNIL. As an indication:
- Prospects and contact requests: 3 years from the last unanswered contact.
- Clients (commercial relationship): throughout the relationship, then in intermediate archiving for 3 years from the last interaction.
- Accounting documents and supporting records (invoices): 10 years (Article L123-22 of the French Commercial Code).
- Payslips and HR data of employees: 5 years (Article L3243-4 of the French Labour Code).
- Data of unsuccessful job applicants: a maximum of 2 years after the last contact, unless erasure is requested.
- Training files and certificates: retained in accordance with our regulatory obligations, then archived.
- Newsletter subscription: until withdrawal of your consent (unsubscribe).
- Cookies and trackers: maximum 13 months (see our cookie management policy).
The same data may be used for separate processing operations subject to different retention periods: archiving or deleting it in one processing operation does not prevent its continued use in another. At the end of the applicable periods, your data is deleted or anonymised.
8. Security
BCIT implements appropriate technical and organisational measures to protect your data against unauthorised destruction, loss, alteration, disclosure or access, in line with its cybersecurity expertise.
9. Your rights
In accordance with the GDPR, you have the following rights over your personal data:
- Right of access: obtain confirmation that data concerning you is being processed and obtain a copy of it.
- Right to rectification: have inaccurate or incomplete data corrected.
- Right to erasure: request deletion of your data under the conditions provided for by law.
- Right to object: object to the processing of your data on legitimate grounds or for direct marketing purposes.
- Right to data portability: receive the data you provided in a structured, machine-readable format.
- Right to restriction: request the temporary suspension of processing of your data.
10. Exercising rights and contacting the DPO
You can exercise your rights by contacting BCIT via our page contact or by writing to our data protection officer (DPO), Corentin BARDIN, at the address dpo@bcit.fr. Proof of identity may be requested. BCIT undertakes to respond within one month, extendable depending on the complexity of the request.
11. Cookies
Our website uses only cookies that are strictly necessary for its operation and security. To learn more about their nature and purpose, please consult our cookie management policy.
• Complaint to the CNIL (
If, after contacting us, you believe that your rights are not being respected, you may lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or via its website www.cnil.fr.
10. Policy update
This policy may be amended at any time to take account of legal, regulatory or technical developments. We invite you to consult it regularly. The date of the last update appears below.