Skip to content

Privacy and GDPR

FitRadarHR was designed with GDPR compliance as a design constraint, not a layer added after the fact.

Data collected

Data Who Duration Legal basis
Email, first name, last name (account users) Account users Duration of the account Contract
Email, first name, last name (evaluated people) Candidates / employees Duration of the organization Legitimate interest + consent
Questionnaire answers (raw) Evaluated people Deleted after calculation Consent
Big Five scores Evaluated people Duration of the organization Consent
Fit reports Evaluated people Duration of the organization Legitimate interest

Before answering the questionnaire, each person reads and explicitly accepts an information notice. This consent is: - Recorded with a timestamp and the version of the text displayed - Immutable (cannot be modified afterward) - Revocable (the person can request erasure of their data)

Right to erasure

At the request of an evaluated person, their personal data (first name, last name, email) is anonymized ([deleted]). Associated fit reports are kept without a nominative link, for organizational traceability.

Audit log

All sensitive actions (viewing a report, PDF export, sending a link, erasure) are recorded in an immutable log — in line with EU AI Act requirements for high-risk systems (see EU AI Act and recruitment for the timeline and the detail of obligations).

Audience measurement

FitRadarHR uses Matomo, self-hosted on the same infrastructure, to know usage volume and the most used features. This measurement is configured under CNIL consent exemption: no cookie, anonymized IP, no personal data collected, no data transmitted to a third party. No consent banner is therefore displayed for this use — to be distinguished from the explicit consent required for the Big Five questionnaire (see above), which remains unchanged.

Product usage analysis (optional)

Unlike the audience measurement above, this analysis is disabled by default: it only exists if the instance operator has configured a Mixpanel key. On a self-hosted instance without that key, no data leaves the server.

When enabled, the instance sends Mixpanel (third-party processor) events describing how signed-in professional users — HR staff and managers — use the application: viewing a report, exporting a PDF, creating an organisation, subscribing.

  • Server-to-server. No Mixpanel script is loaded in the browser, and no cookie or identifier is written to your device. No consent banner is required on this basis.
  • EU residency. Raw events are hosted in Mixpanel's European region. Account and billing metadata remain processed in the United States by Mixpanel Inc., under the EU–US Data Privacy Framework.
  • Absolute boundary. Events from the Big Five questionnaire and from the personal portal are never transmitted. No identifier, name, email address or personality score of an assessed person ever leaves the server.

If you self-host and enable this option

Mixpanel becomes one of your processors: sign the data processing agreement (DPA), add it to your Article 30 record of processing activities, and mention it in your own privacy policy. Internal technical documentation (docs/technical/analytics.md) covers the configuration.

Hosting

FitRadarHR is self-hosted. You control where your data resides. In its default configuration, no data is transmitted to any third party — the only possible exception is the product usage analysis described above, which stays off until a key is configured.

Self-hosting

By deploying FitRadarHR on your own VPS, you are responsible for the processing of personal data (data controller role). Remember to update your records of processing activities.