

Privacy Policy
Last updated: MARCH 27, 2026
At BLIFY, respecting your privacy and protecting your personal data is our priority.
This privacy policy (the "Privacy Policy") aims to inform you about the conditions under which your personal data is processed in connection with your use of the website https://www.blify.co/ (the "Site") and the BLIFY services available via the BLIFY platform and through integration with Teams, Slack, or WhatsApp software (together, our "Services"), in accordance with Regulation (EU) 2016/679 of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "GDPR") and French Law No. 78-17 of January 6, 1978 on information technology, data files and civil liberties in its latest applicable version (together, the "Applicable Regulations").
This Privacy Policy does not describe the methods of collection and processing of your data via cookies and other trackers ("Cookies") on the Site. To find out more, please consult our Cookie Policy.
Words beginning with a capital letter have the same meaning as that given to them in our Terms and Conditions.
Who is the Data Controller?
The legal classification of BLIFY varies depending on the nature of the processing:
When you browse our Site, or more generally in the context of managing our contractual relationship with you, the data controller is BLIFY, a simplified joint-stock company (société par actions simplifiée), registered with the Nanterre Trade and Companies Register (RCS) under number 941 613 739, with its registered office located at 32 Rue de Paris, 92100 Boulogne-Billancourt, France ("We", "Us", "Our").
Regarding data relating to Users, processed as part of the performance of the Services (in particular, sending quizzes, collecting answers, etc.), We collect and process Users' personal data in the name and on behalf of our clients (the employers who subscribe to our Services). Our clients are therefore the data controllers, and we act as a data processor. Consequently, such processing is excluded from the scope of this Privacy Policy. The processing we carry out as a data processor is governed by the personal data clause of our General Terms of Use. However, we may reuse your data relating to the use of the Services (activity tracking data) to improve our Services. In this case, we implement this processing as a data controller.
What data do we collect?
Personal data is any data that makes it possible to identify an individual directly or by cross-referencing with other data.
We collect personal data falling into the following categories:
As part of Our business relationship:
Identification data (last name, first name, email and postal address, phone number);
Browsing data (IP address, pages viewed, date and time of connection, browser used, operating system, user ID, MAID);
Data from recordings of phone calls between you and our customer service (the content of the calls, their dates);
Any information you wish to transmit to us as part of your contact request.
As part of our recruitment processes: data relating to your professional life (company name, resume/CV, position/role, LinkedIn URL if provided);
As part of the use of our Services: data relating to Users' activity (role, company, type of activity created, answers to questions, number of role-plays completed, messages sent, button clicks).
Mandatory data is indicated when you provide us with your data. It is signaled by any appropriate means.
Details on the processing of your personal data
Purposes | Legal Basis | Retention Periods |
Building a prospect database | Our legitimate interest in developing and promoting our business. | Your data is kept for 3 years from your last contact with us. |
Managing prospects and clients (quotes, monitoring the contractual relationship) | Performance of the contract you or your company has entered into with Us. | Personal data is kept for the duration of the contractual relationship. Additionally, data is archived for evidentiary purposes for 5 years. |
To analyze your use of our Services, understand your expectations, and improve the features offered as part of our Services (in particular by analyzing communications, compiling browsing and audience statistics for the Site, and analyzing Users' activity tracking data). | Our legitimate interest in improving our services. | Telephone recordings with our customer service are retained for up to 6 months, and analysis documents are retained for up to 1 year. Personal data collected via Cookies to improve the user experience is retained for 90 days. Personal data collected during your use of the Services is retained for 12 months. Once anonymized, your data is no longer considered personal data, as no re-identification is possible. It is retained for as long as necessary. |
Sending newsletters, solicitations, and promotional emails | Our legitimate interest in retaining clients and informing them/prospects of our latest news. | Data is kept for 3 years from your last contact with Us. |
Responding to information, contact, and/or demo requests | Execution of pre-contractual measures taken at your request. | Data is kept for 3 years from your last contact. |
Retaining administrative information and documents | Compliance with our legal and regulatory obligations. | Invoices: 10 years. Transaction data (excluding bank details): 5 years. Contract data and signature elements: 5 years. |
Processing job applications and managing recruitment (screening, contacting candidates, interviews, finalizing recruitment) | Execution of pre-contractual measures taken at your request. | Active database: duration of the recruitment process until a hiring decision is made. If rejected: 3 months post-recruitment to provide explanations for the rejection. Intermediate archiving for evidentiary purposes: 5 years from the hiring decision date. |
Building a resume database | Your consent. | Data is kept for 2 years from the last contact with the data subject. |
Responding to data subject rights requests | Compliance with our legal and regulatory obligations. | Proof of identity (if requested): kept only for the time necessary to verify identity, then deleted. Opt-out requests for marketing: kept for 3 years. |
Who are the recipients of your data?
The following parties will have access to your personal data:
Our company’s staff;
Our subcontractors and service providers (hosting provider, newsletter distribution, audience measurement and analytics, email provider, secure payment provider, billing tool, cookie management tool, CRM, CMS, automation tools, video conferencing tool, online ad networks, telephony tools, corporate ERP);
Any legally authorized authority, in particular judicial, police, or administrative authorities, upon request.
Are your data likely to be transferred outside the European Union?
Throughout the processing period, your data is kept and stored on Heroku (Amazon Web Services) servers located within the European Union.
Through the tools we use (see the "Recipients" section regarding our subcontractors), your data may be transferred outside the European Union. Transfers in this context are secured using the following mechanisms:
The data is transferred to a country subject to an adequacy decision by the European Commission, per Article 45 of the GDPR (the country ensures a level of protection deemed sufficient and adequate to the GDPR); or
The data is transferred to a country whose data protection level has not been recognized as adequate: in this case, transfers are based on appropriate safeguards per Article 46 of the GDPR, tailored to each provider. These include, but are not limited to, Standard Contractual Clauses (SCCs) approved by the European Commission, Binding Corporate Rules (BCRs), or an approved certification mechanism; or
The data is transferred based on one of the appropriate safeguards described in Chapter V of the GDPR.
You can obtain a copy of the safeguards used to transfer your data outside the European Union by contacting us at the details provided in the "What Are Your Rights Regarding Your Data?" section below.
What are your rights regarding your data?
You have the following rights concerning your personal data:
Right to Information: This is exactly why we drafted this Privacy Policy, as required by Articles 13 and 14 of the GDPR.
Right of Access: You have the right to access all your personal data at any time, under Article 15 of the GDPR.
Right to Rectification: You can request the correction of inaccurate, incomplete, or outdated personal data at any time, per Article 16 of the GDPR.
Right to Restriction of Processing: You may request that we limit the processing of your data in specific cases outlined in Article 18 of the GDPR.
Right to Erasure (Right to be Forgotten): You have the right to request the deletion of your personal data and prohibit future collection for reasons stated in Article 17 of the GDPR.
Right to Digital Legacy: You can define directives regarding the retention, deletion, and communication of your personal data after your death.
Right to Withdraw Consent: For purposes based on consent, Article 7 of the GDPR allows you to withdraw your consent at any time. This withdrawal will not affect the lawfulness of processing carried out before the withdrawal.
Right to Data Portability: Under certain conditions specified in Article 20 of the GDPR, you can receive the personal data you provided to us in a standard, machine-readable format and require its transfer to a recipient of your choice.
Right to Object: Under Article 21 of the GDPR, you have the right to object to the processing of your personal data. Please note, however, that we may continue processing despite this objection for legitimate grounds or the defense of legal claims.
You can exercise these rights by writing to us at the following address: privacy@blify.co
In cases of reasonable doubt, we may ask you to provide additional information, including documents to verify your identity.
If you have any questions or requests that remain unresolved, you have the right to lodge a complaint with the competent supervisory authority. In France, this is the Commission Nationale de l'Informatique et des Libertés (CNIL), located at 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07.
Amendments
We may modify this Privacy Policy at any time, particularly to comply with any regulatory, jurisprudential, editorial, or technical developments. These changes will apply as of the effective date of the modified version. We invite you to regularly review the latest version of this policy. However, we will notify you of any significant changes to this Privacy Policy.
Effective Date: February 27, 2026


