Privacy policy
Last updated: September 17, 2026
Koragence only collects the data needed to answer requests, process applications, secure forms, and measure website usage after consent. Forms are stored in a PostgreSQL database hosted in Europe, and notifications are delivered through Mailgun. Audience measurement and session replay rely on PostHog Cloud configured on its European services, only after explicit consent.
Data controller
KORAGENCE SASU, 47 boulevard de Courcelles, 75008 Paris, France. Contact: contact@koragence.com.
Allocation of roles
Koragence is controller for its own purposes: managing incoming requests, commercial exchanges, quotes, billing, project management, security of its systems, abuse prevention, and consented audience measurement.
When a Client determines the purposes and means of processing its business data, it acts as controller. Koragence acts as processor when its teams process that data only on the Client’s behalf and on documented instructions. A GDPR Article 28 data processing agreement must then supplement the contract.
Data collected
- Contact, project, or application forms: name, email, company if relevant, profile link, subject, free-form message, project information, and data you choose to send.
- Security and anti-spam: IP address, user agent, referrer, language, timestamp, limited technical fingerprint, anti-spam check result, and information needed to limit abuse.
- Audience measurement after consent: acquisition source, UTM parameters, pageviews, clicks, scroll depth, language, browser, device type, viewport size, and a pseudonymous visitor identifier.
- Session replay after consent: visual reconstruction of navigation, with form fields masked and areas marked as sensitive excluded.
- No banking data is collected on this website.
Purposes and legal bases
- Answering your requests, preparing a commercial exchange or a pre-contractual relationship: GDPR Article 6(1)(b).
- Processing an application submitted through the website: pre-contractual measures or legitimate interest depending on the context.
- Measuring audience, understanding journeys, and improving the site with PostHog: consent, GDPR Article 6(1)(a).
- Securing forms, limiting spam, preventing abuse, and keeping necessary technical proof: legitimate interest, GDPR Article 6(1)(f).
Processing: contact and project requests
Purpose: answer a request, understand the project, and prepare a discussion or quote. Data: identity, email, company, industry, project type, message, deadline, and any files or information voluntarily provided. Legal basis: pre-contractual measures where the request concerns a service; legitimate interest for form security. Required fields are necessary to respond; optional fields may be left blank. Recipients: Koragence and technical subprocessors needed for hosting, storage, and notification. Retention: up to 3 years after the last meaningful commercial exchange, then deletion or anonymisation, unless a legal obligation or dispute requires otherwise. Transfers outside the EU/EEA may occur depending on providers and their subprocessors and must be covered by applicable safeguards.
Processing: applications
Purpose: review an application and organise recruitment discussions. Data: identity, contact details, profile link or CV, message, and information provided by the applicant. Legal basis: pre-contractual measures or legitimate interest depending on the recruitment stage. Information needed to review the application is required; without it, the application may not be processed. Recipients: authorised Koragence staff and technical providers used to store and notify the application. Retention: for the duration of the process, then deletion; the current form does not activate a future-opportunities talent pool. If one is created, it must have separate information and legal basis, with retention no longer than 2 years after the last contact.
Processing: security and anti-spam
Purpose: limit abuse, detect automated submissions, protect the API, and retain information needed to investigate an incident. Data: IP address where available, user agent, referrer, timestamp, browser proof, honeypot fields, moderation score, and reasons. Legal basis: legitimate interest. This data is not required to browse the website but may be required to accept a submission. Recipients: Koragence and the relevant technical hosting, storage, and security providers. Retention: up to 12 months for ordinary anti-spam records, longer only where an incident, abuse, or evidentiary obligation justifies it.
Processing: audience measurement and session replay
Purpose: understand journeys and improve the website. Legal basis: consent collected through the banner with equivalent options to accept, refuse, or customise. Data: pageviews, clicks, scroll depth, acquisition source, technical information, and a pseudonymous identifier; session replay only where enabled after consent. PostHog is configured through its European endpoints in the inspected environment. Documented retention is a maximum of 13 months for analytics and 3 months for replay, subject to validation of production account settings. Consent can be withdrawn through “Cookies”; refusal blocks initialisation.
Other detected processing
No AI provider executed by the website, advertising pixel, CAPTCHA, or separate marketing tool was detected in the inspected code. Services delivered for Clients may involve additional processing: it must then be described in the contract, DPA, and applicable documented instructions.
European PostHog Cloud, cookies, and session replay
PostHog Cloud is used on its European services for audience measurement, journey tracking, conversions, and session replay. It does not start before explicit analytics consent through the cookie banner. If consent is refused, the website only stores the consent choice locally so the same decision is not requested again immediately.
After acceptance, PostHog may use local storage and cookies needed for consented measurement. The configuration masks form fields, excludes sensitive areas marked in code, removes free-form content, phone numbers, and plain-text emails from analytics events, and allows consent withdrawal at any time from the “Cookies” link in the footer.
Retention periods
- Commercial requests and forms: up to 3 years after the last meaningful exchange.
- Applications: up to 2 years after the last contact, unless earlier deletion is requested or a contrary obligation applies.
- Technical anti-spam and security data related to forms: up to 12 months, except in case of incident, abuse, or evidentiary obligation requiring longer retention.
- Audience measurement data: up to 13 months after collection.
- Session replay: up to 3 months.
- Cookie consent choice: stored locally for 6 months before asking for your choice again.
Recipients, hosting, and transfers
The data is intended for Koragence and its strictly necessary technical subprocessors: website hosting, database, technical form delivery, security, and consented analytics. The website notably uses Vercel for hosting in the Paris, France (cdg1) region, a database hosted in Europe, Mailgun through its European endpoint for form delivery, and PostHog Cloud through its European services for audience measurement after consent.
Koragence does not sell or rent personal data and does not disclose it for targeted advertising or the creation of commercial files. Technical providers may process data on Koragence’s behalf only for the purposes described here; this is not a resale or commercial disclosure. The regions, retention periods, further subprocessors, and any transfers outside the EU/EEA must be confirmed in the production accounts and contracts for the technical services used before stating that no transfer occurs.
Security and minimisation
Koragence limits collected data to what is useful for the requested processing or website security. Forms are marked to avoid automatic capture by analytics tools, sensitive fields are masked in session replay, analytics events are filtered, and data access is restricted to people or providers who need it.
Your rights
You may exercise your rights of access, rectification, deletion, restriction, objection, portability, and withdraw analytics consent at any time by writing to contact@koragence.com or by using the “Cookies” link in the footer.
You may also lodge a complaint with the CNIL.