Legal information
Privacy notice
How Postule Moi processes account, CV, job-search, coaching, billing and technical data.
Updated · 31 August 2026Controller and data categories
Controller: Eric Salle, entrepreneur individuel exerçant sous le nom commercial TrajectIA, 81 rue Le Caravage, 34000 Montpellier, France — SIREN 108 606 666 — SIRET 108 606 666 00015 — RCS Montpellier 108 606 666 — APE 6201Z — TVA non applicable, article 293 B du CGI. Privacy contact: contact@traject-ia.com. Data processed includes identity and authentication, profile, photo and CV, search criteria, job interactions, applications and coaching answers, subscription and invoice metadata, consent, support, audit and security logs. Card data is handled by the active payment provider and is not stored by Postule Moi.
Purposes and legal bases
Contract necessity supports account and requested features; legitimate interests support proportionate security, fraud prevention and service measurement; legal duties support accounting and compliance; consent supports optional cookies, marketing and external AI processing where required. A form indicates mandatory fields and the consequence of not providing them.
AI, recipients and international transfers
The main service is hosted on an OVHcloud/Kimsufi dedicated server in Limburg, Germany (eu-west-lim). PostgreSQL, Stalwart and ClamAV are self-hosted there. Depending on the selected feature and configuration, external recipients may include OpenAI or Mistral AI for consented AI processing, Stripe or Mollie for payments, and enabled Google, LinkedIn, Apple, Kakao and job-source integrations. DPA records, subprocessors and any non-EEA transfers for each active provider remain subject to verification before launch.
Retention and security
The account is retained while active; a warning is planned after 24 months of inactivity and deletion after 36 months. Product content and AI history follow the account or an available earlier deletion. Support is retained for 3 years after closure, transactional notifications for 6 months, application logs for 6 months, security and audit events for 12 months, and justified security incidents for up to 24 months after closure. Necessary consent evidence may be retained for up to 5 years, marketing prospects for 3 years after the last relevant contact, and legally required accounting documents for 10 years. Exports expire technically. Off-host backups are not active yet; their planned maximum rotation is 30 days.
Your rights and contact
Subject to applicable law, you may request access, correction, erasure, restriction, portability or objection, withdraw consent without affecting earlier processing and complain to the CNIL. Requests can be made in My Account or at contact@traject-ia.com, with identity checks where necessary, and are answered within the legal deadline, normally one month under GDPR.