The public front office does not embed third-party audience analytics or visitor fingerprinting.
Privacy & personal data
MyProID limits collection to what is needed, separates public use from authenticated spaces and documents the processing actually present in this version.
Profile views and vCards may increment counters without identifying unique visitors.
Contact, reports and partner applications are encrypted server-side before admin storage.
Switzerland is covered by a European Commission adequacy decision for personal-data transfers.
Who determines the processing?
For processing operated directly by MyProID, the controller is Mehdi Kachouri for Koperateur Consulting, based in Pau, France. Profile owners remain responsible for the personal data and content they choose to publish.
The MyProID Contact form is the public entry point for privacy requests. No DPO is presented as appointed in the current version.
- Controller
- Mehdi Kachouri · Koperateur Consulting
- Location
- Pau (64000), France
- Contact
- MyProID Contact form
What data may be processed?
The scope depends on whether you simply view a profile, create an account, manage a profile, use optional Google sign-in or submit a public form.
- Account: full name, email, password hash, optional phone and professional link, internal identifiers and account status.
- Profile: professional information, contact details, media, links, services and availability chosen by the owner.
- Optional Google sign-in: Google identifier, email, name and, where provided and no local photo exists, profile-picture URL.
- Contact form: name, email, subject and message.
- Report form: email, relevant URL and description.
- Partner form: name, email, online presence, estimated audience and message.
- Public metrics: aggregate counters rather than visitor identifiers.
- Security: technical data required for sessions, rate limiting, origin checks and server logs.
Why is data used?
Processing is limited to operating and protecting the service. MyProID does not announce the sale of personal data or visitor advertising profiles.
- Create and authenticate accounts.
- Publish and update professional profiles at the owner’s request.
- Handle contact, reports and partner applications.
- Measure global usage through aggregate counters.
- Prevent abuse and protect accounts.
- Meet legal or administrative obligations where applicable.
Legal bases
Account creation and service delivery primarily rely on performance of the requested service or pre-contractual steps. Security and abuse prevention may rely on legitimate interests. Legal and accounting duties, where applicable, rely on legal obligation.
The legal basis for a public form depends on the request: pre-contractual steps for a service request, or legitimate interests for general enquiries, reports and partner applications. Google sign-in is used only when selected by the user.
Consent is not presented as the default basis for every processing activity.
Public browsing, theme and metrics
Public browsing does not intentionally create an analytics visitor identifier. Aggregate view counters can increase on refresh and are not unique-visitor figures.
The light/dark preference is stored locally in the browser and is not used as a marketing identifier.
No third-party analytics, JavaScript CDN or remote font is loaded by default on the public front office.
Session cookie and local storage
Static public pages do not intentionally start a session when no MyProID session already exists. Authentication flows and private areas use a session cookie named myproid_session.
The cookie is configured HttpOnly, SameSite=Lax and Secure over HTTPS. It maintains the authenticated session and related security controls rather than measuring audience.
The light/dark theme preference is stored in browser local storage. Public aggregate counters do not create a persistent analytics cookie.
Contact, reports and partner applications
Public form content is validated server-side, encrypted and then stored in the administration inbox. The stored payload explicitly removes IP address, User-Agent, fingerprint, device ID and visitor ID fields.
A minimal email can announce a new message without copying its content. Anti-abuse controls may still temporarily use technical network information outside the encrypted message itself.
Google sign-in
Google OAuth is optional. MyProID requests openid, email and profile scopes and receives a Google identifier, name and verified email.
If no local avatar exists, the current code may store the Google-hosted profile-picture URL. Displaying it can therefore create a request to Google. Users can avoid this by using standard authentication or replacing the picture locally.
The service is not described as completely third-party-free when Google OAuth or an external Google profile image is used.
Hosting, recipients and Switzerland
Primary infrastructure is hosted by Infomaniak Network SA in Switzerland. Access is limited to authorized MyProID administrators and service providers necessary to operate the service according to their role.
Switzerland is recognised by the European Commission as providing an adequate level of protection for personal-data transfers.
- Primary host
- Infomaniak Network SA · Switzerland
- EU status
- European Commission adequacy decision
- Internal recipients
- Authorized people handling administration and requests
- Optional third party
- Google for OAuth and possible external profile image
Retention periods
Account and profile data are kept while necessary to operate the account and service, subject to applicable legal duties.
The current code does not announce an automatic fixed purge deadline for encrypted inbox messages. They can be marked new, open, replied or archived. A precise purge schedule should be formalised before large-scale commercial operation.
Aggregate metrics are not designed to identify individual visitors.
A retention period is not invented when the product does not yet enforce one.
Security measures and limits
The project uses password hashing, protected sessions, CSRF, server-side validation, prepared queries, restrictive CSP, rate limiting, origin checks, upload restrictions and authenticated encryption for the public inbox.
These controls reduce risk but cannot eliminate human error, vulnerabilities, compromised accounts, hosting incidents or attacks.
Access, correction, deletion and other rights
Depending on the processing and its legal basis, you may request access, correction, deletion, restriction, objection or portability where applicable, and withdraw consent when consent is actually the legal basis.
Use the Contact form to exercise a right. Proportionate identity verification may be required. People in France may also lodge a complaint with the CNIL.
Data-protection framework
Transparency requirements and the status of transfers to Switzerland can be checked with competent authorities.
Use only what you need
Start simply and activate only the features useful to your professional context.
