Privacy policy
Ghost World Society C corp processes your personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act. This page explains what data we collect, why, for how long, and your rights.
Last updated: August 31, 2026
Data controller
Ghost World Society C corp, 12 rue du Sentier, 75002 Paris, France — Paris Trade Register 941 234 567. Data protection officer: privacy@ghost.fr.
Data we collect
Depending on how you use the site: identity and contact details (first name, last name, email, phone, company); the content of the descriptions and files you submit to generate a mockup; application data (resume, professional link, message, source); booking data (slot, context); technical data (truncated IP address, browser, pages viewed); proof of consent (date, version of the text accepted).
Purposes and legal bases
Mockup generation and customer workspace: performance of the contract or pre-contractual measures.
Booking calls, answering contact requests: pre-contractual measures and our legitimate interest in replying to you.
Recruiting: pre-contractual measures and your consent to keep your application on file.
Security, fraud prevention, technical logs: legitimate interest.
Audience measurement through analytics cookies: consent.
Retention periods
Anonymous mockup-generation sessions: 30 days after the last activity, or until linked to an account.
Customer account: for the duration of the relationship, then 3 years after the last sign-in.
Contact requests and bookings: 3 years after the last exchange.
Job applications: 12 months after receipt, unless you ask for earlier deletion; resumes are scanned by antivirus software and deleted at the end of that period.
Technical logs and proof of consent: 12 months; audit logs: 12 months; accounting records: 10 years (legal obligation).
Recipients and processors
Your data is accessible only to the Ghost team members who need it (dedicated expert, recruiting, support). Our processors handle hosting (Railway, servers in Amsterdam, the Netherlands), transactional email delivery (Resend) and antivirus scanning of uploaded files. No data is ever sold or shared with third parties.
Transfers outside the European Union
Your data is hosted and processed in the European Union. Should a transfer outside the EU become necessary, it would be governed by the European Commission's standard contractual clauses and you would be informed.
Your rights
You have the right to access, rectify, erase, restrict, port and object to the processing of your data, as well as the right to withdraw your consent at any time and to set instructions for your data after death.
Exercise them by writing to privacy@ghost.fr or by mail to our registered office; we reply within one month. You may also lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr).
Security
Encryption in transit (TLS) and of secrets at rest (AES-256), role-based access control, audit logs, antivirus scanning of received files, sovereign hosting in the European Union. Our team's access is individual and logged.
Changes
This policy may change; the last-updated date appears at the top of the page. In case of a substantial change, users with an account are notified by email.