This policy explains what personal data the simplevisa.com website collects, why, on what legal basis, who receives it, and what rights you have. It is written to be read, not skimmed past. It covers this marketing website only.
One thing this site does not do: it collects no passport, visa-application or traveller data. Travellers apply at apply.simplevisa.net, which has its own privacy policy covering that processing.
Data controller
The data controller is Simple, a French société par actions simplifiée (SAS), registered under SIREN 849 878 780 (RCS Bordeaux), with its registered office at 58 avenue Marcel Dassault, 33700 Mérignac, France. Simple operates the SimpleVisa service.
Privacy contact: via our contact form or by post to the registered office, marked "Données personnelles". Simple has not appointed a data protection officer; the privacy contact above is the dedicated contact point.
What we process, why, and on what basis
| Processing | Data | Purpose and legal basis | Retention |
|---|---|---|---|
| Serving and securing the site | IP address, browser and device details, requested URLs, timestamps (technical logs) | Delivering pages, maintaining availability, detecting abuse and investigating incidents — legitimate interests (art. 6(1)(f) GDPR): keeping the site running and safe | Rolling 12 months; incident evidence longer only where justified |
| Demo requests | Name, work email, company, message — mandatory fields are marked on the form; without them we cannot respond | Answering the request and taking the pre-contractual steps you asked for — art. 6(1)(b); where you enquire on an employer's behalf, our legitimate interest in handling B2B enquiries (art. 6(1)(f)) | 3 years from the last contact you initiate if no customer relationship results (the CNIL prospecting reference), then deleted |
| Coverage-alert and topic subscriptions | Email address and the topics you selected | Sending the updates you explicitly subscribed to — consent (art. 6(1)(a)), withdrawable at any time via the unsubscribe link in every email | Until you unsubscribe, then only the minimal suppression record needed to honour the objection |
| Consent records | A random visitor identifier, your accept/refuse choices, banner version, browser user-agent, timestamp — deliberately no IP address | Remembering your cookie choices and being able to demonstrate them — legal obligation to prove consent (art. 7(1)) and legitimate interest in demonstrating compliance | Choices are re-asked after at most 6 months (CNIL recommendation); proof records kept as long as needed to demonstrate compliance |
| Audience measurement (PostHog, Google Analytics 4) | Cookies and similar identifiers, usage and event data, approximate location; PostHog also makes session recordings — a replay of pages viewed, scrolling and clicks, with everything typed into any field masked before it leaves your browser | Understanding how the site is used — prior consent (art. 82 of the French Loi Informatique et Libertés and art. 6(1)(a) GDPR). These tools load only after you accept the analytics purpose in the cookie banner | As configured per tool; current lifetimes are listed in the cookie policy |
| Advertising measurement and remarketing (Google Ads, Meta Pixel, LinkedIn Insight Tag) | Cookies and advertising identifiers, conversion events, matching data | Measuring campaigns and building advertising audiences — prior consent (art. 82 and art. 6(1)(a)), only after you accept the advertising purpose in the banner | As configured per platform; see the cookie policy |
We do not use your data for purposes other than those listed. If a materially new purpose ever arises, you will be informed first, and asked for consent where consent is the basis.
Recipients
Internally, data is accessible to the Simple team members who need it for the purposes above. Externally, we use the following categories of recipients: our hosting provider (Infomaniak Network SA, Switzerland), and — only after your consent — the analytics and advertising providers below. Professional advisers and public authorities receive data only where the law requires it.
| Service | Provider (EU users) | Role and transfers |
|---|---|---|
| PostHog (analytics) | PostHog Inc., San Francisco, USA — data hosted on PostHog Cloud EU (Frankfurt, Germany) | Our processor. Any US access is covered by PostHog Inc.'s active EU–US Data Privacy Framework certification — privacy policy |
| Google Analytics 4, Google Tag Manager, Google Ads | Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland | Processor for measurement data, independent controller for parts of its advertising processing; onward processing by Google LLC (USA) under Google LLC's Data Privacy Framework certification — privacy policy |
| Meta Pixel | Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland | Jointly responsible with us for the collection and transmission the Pixel performs; onward processing by Meta Platforms, Inc. (USA) under its Data Privacy Framework certification — privacy policy |
| LinkedIn Insight Tag | LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland | Insight Tag data is stored on US servers by LinkedIn Corporation under its Data Privacy Framework certification — privacy policy |
Transfers outside the EU
Where data reaches the United States through the providers above, the transfer relies on the EU–US Data Privacy Framework (an adequacy decision under art. 45 GDPR) for recipients holding an active certification, upheld by the EU General Court in September 2025; an appeal is pending before the Court of Justice. Where a recipient's certification lapses or the framework's status changes, the providers' standard contractual clauses apply as the fallback safeguard. You can obtain details of the applicable safeguards through the privacy contact above.
Your rights
You can ask for access to the data we hold about you, have it corrected or erased, ask for processing to be restricted, object to processing based on our legitimate interests, and receive data you provided in a portable format. Where processing rests on consent, you can withdraw it at any time without affecting what was lawfully done before — for cookies, through the "Cookie settings" link in the footer; for subscriptions, through the unsubscribe link in any email. Objection to direct marketing is unconditional and always available.
Under article 85 of the French Loi Informatique et Libertés, you can also give us instructions on what happens to your data after your death.
To exercise any of these rights, use the contact form or write to the registered office. We respond within one month and ask for proof of identity only where reasonably necessary to protect your data. If you believe we have not handled your data properly, you can lodge a complaint with the CNIL: cnil.fr/fr/adresser-une-plainte, or CNIL — Service des plaintes, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.
No automated decisions
This site makes no automated decisions producing legal or similarly significant effects about you (art. 22 GDPR). Advertising tools may build audience profiles from consented data, as described above; nothing on this site decides anything about you by algorithm.
Security
Data is transmitted over encrypted connections and stored with access limited to those who need it. Consent records deliberately exclude IP addresses. No system is perfectly secure and we do not claim ours is; we design so that this site holds as little personal data as the job allows.
Changes
The revision date at the top of this page moves when the content changes, and only then. Material changes — a new purpose, a new category of recipient — are announced on this page before they take effect, and consent is re-sought where consent is the basis. Continued browsing is never treated as acceptance.