Privacy and hosting

Your data stays in Europe, and we collect as little of it as possible.

A team building session produces little data, but it belongs to your employees. Here, without jargon, is where it lives, for how long, and what we never do with it.

GermanyServers operated by netcup GmbH, Karlsruhe. Data centres in Germany and Austria, within the European Union.
GDPR agreementA data processing agreement compliant with Article 28 of the GDPR is signed with the host, covering its technical and organisational measures.
ISO 27001The host is certified to ISO 27001 (information security), ISO 27701 (data protection) and ISO 9001.

Where the servers are

The platform runs on a dedicated server rented from netcup GmbH, a German company in the Anexia group, headquartered in Karlsruhe. The data centres used are located in Nuremberg and Vienna: access control, video surveillance, redundant power and cooling, and staff bound by confidentiality.

No session data is stored outside the European Union. Exchanges between the phones, the screen and the server are encrypted over HTTPS.

What we collect during a session

  • Team names and, if the company wishes, participants’ first names, entered on site.
  • Answers to challenges, scores and response times, by team.
  • Team photos taken voluntarily during a challenge, when the programme includes one.
  • A technical identifier per phone, for the duration of the session, to reconnect the device if the Wi-Fi drops.

What we don’t collect

  • No account to create, no password, no participant email addresses.
  • No app installed, so no access to the phone’s contacts, photos or location.
  • No advertising trackers, no selling or sharing of data with third parties.
  • Votes and contributions that a programme designates as “anonymous” really are anonymous: they are not linked to any phone.

How long

Session data is used to produce the report delivered to the company. It is kept for thirty days after the event, long enough to approve the report, then deleted. The company can request immediate deletion.

One instance per client

Each company has its own instance, on its own subdomain. Two clients’ data never mix, neither on screen nor on the server.

Job applications

When you apply for a job or send a speculative application from corporatesolutions.live/carrieres, Corporate Solutions is the controller of this data.

  • Purpose: to review your application and reply to you. A speculative application may be reviewed again when a position opens.
  • Data: your name, email, message and CV, the position applied for, your phone number and LinkedIn or portfolio link if you provide them, the date sent and the IP address (to limit abusive submissions).
  • Access: only the recruitment team can view them, from a protected area. Your CV is stored on our servers in the European Union, outside the public website, and is never published or shared with third parties. The new-application notice emailed to the team does not include the CV.
  • Retention: 24 months after submission, then automatic deletion, CV included.
  • Your rights: access, rectification and deletion at any time, on simple request to contact@corporatesolutions.live.

Your rights

Corporate Solutions acts as a processor on behalf of the client company, which remains the data controller. A data processing agreement can be signed with each client on request. Any question or request for access, rectification or erasure can be sent to the contact address shown on the home page.