Privacy by design

Privacy & personal data

MyProID limits collection to what is needed, separates public use from authenticated spaces and documents the processing actually present in this version.

Hosting in Switzerland, reduced public collection, aggregate metrics and encrypted public forms reduce exposure without providing an absolute guarantee.
Last updated : 23 août 2026Controller in France · primary hosting in Switzerland
No third-party public analytics

The public front office does not embed third-party audience analytics or visitor fingerprinting.

Aggregate counters

Profile views and vCards may increment counters without identifying unique visitors.

Encrypted public forms

Contact, reports and partner applications are encrypted server-side before admin storage.

Switzerland has EU adequacy

Switzerland is covered by a European Commission adequacy decision for personal-data transfers.

01
Controller

Who determines the processing?

For processing operated directly by MyProID, the controller is Mehdi Kachouri for Koperateur Consulting, based in Pau, France. Profile owners remain responsible for the personal data and content they choose to publish.

The MyProID Contact form is the public entry point for privacy requests. No DPO is presented as appointed in the current version.

Controller
Mehdi Kachouri · Koperateur Consulting
Location
Pau (64000), France
02
Data categories

What data may be processed?

The scope depends on whether you simply view a profile, create an account, manage a profile, use optional Google sign-in or submit a public form.

  • Account: full name, email, password hash, optional phone and professional link, internal identifiers and account status.
  • Profile: professional information, contact details, media, links, services and availability chosen by the owner.
  • Optional Google sign-in: Google identifier, email, name and, where provided and no local photo exists, profile-picture URL.
  • Contact form: name, email, subject and message.
  • Report form: email, relevant URL and description.
  • Partner form: name, email, online presence, estimated audience and message.
  • Public metrics: aggregate counters rather than visitor identifiers.
  • Security: technical data required for sessions, rate limiting, origin checks and server logs.
03
Purposes

Why is data used?

Processing is limited to operating and protecting the service. MyProID does not announce the sale of personal data or visitor advertising profiles.

  • Create and authenticate accounts.
  • Publish and update professional profiles at the owner’s request.
  • Handle contact, reports and partner applications.
  • Measure global usage through aggregate counters.
  • Prevent abuse and protect accounts.
  • Meet legal or administrative obligations where applicable.
05
Visitors

Public browsing, theme and metrics

Public browsing does not intentionally create an analytics visitor identifier. Aggregate view counters can increase on refresh and are not unique-visitor figures.

The light/dark preference is stored locally in the browser and is not used as a marketing identifier.

No third-party analytics, JavaScript CDN or remote font is loaded by default on the public front office.

06
Browser

Session cookie and local storage

Static public pages do not intentionally start a session when no MyProID session already exists. Authentication flows and private areas use a session cookie named myproid_session.

The cookie is configured HttpOnly, SameSite=Lax and Secure over HTTPS. It maintains the authenticated session and related security controls rather than measuring audience.

The light/dark theme preference is stored in browser local storage. Public aggregate counters do not create a persistent analytics cookie.

07
Messages

Contact, reports and partner applications

Public form content is validated server-side, encrypted and then stored in the administration inbox. The stored payload explicitly removes IP address, User-Agent, fingerprint, device ID and visitor ID fields.

A minimal email can announce a new message without copying its content. Anti-abuse controls may still temporarily use technical network information outside the encrypted message itself.

08
Optional service

Google sign-in

Google OAuth is optional. MyProID requests openid, email and profile scopes and receives a Google identifier, name and verified email.

If no local avatar exists, the current code may store the Google-hosted profile-picture URL. Displaying it can therefore create a request to Google. Users can avoid this by using standard authentication or replacing the picture locally.

Identified third party

The service is not described as completely third-party-free when Google OAuth or an external Google profile image is used.

09
Processors & transfers

Hosting, recipients and Switzerland

Primary infrastructure is hosted by Infomaniak Network SA in Switzerland. Access is limited to authorized MyProID administrators and service providers necessary to operate the service according to their role.

Switzerland is recognised by the European Commission as providing an adequate level of protection for personal-data transfers.

Primary host
Infomaniak Network SA · Switzerland
EU status
European Commission adequacy decision
Internal recipients
Authorized people handling administration and requests
Optional third party
Google for OAuth and possible external profile image
10
Retention

Retention periods

Account and profile data are kept while necessary to operate the account and service, subject to applicable legal duties.

The current code does not announce an automatic fixed purge deadline for encrypted inbox messages. They can be marked new, open, replied or archived. A precise purge schedule should be formalised before large-scale commercial operation.

Aggregate metrics are not designed to identify individual visitors.

Documented limitation

A retention period is not invented when the product does not yet enforce one.

11
Protection

Security measures and limits

The project uses password hashing, protected sessions, CSRF, server-side validation, prepared queries, restrictive CSP, rate limiting, origin checks, upload restrictions and authenticated encryption for the public inbox.

These controls reduce risk but cannot eliminate human error, vulnerabilities, compromised accounts, hosting incidents or attacks.

12
Your rights

Access, correction, deletion and other rights

Depending on the processing and its legal basis, you may request access, correction, deletion, restriction, objection or portability where applicable, and withdraw consent when consent is actually the legal basis.

Use the Contact form to exercise a right. Proportionate identity verification may be required. People in France may also lodge a complaint with the CNIL.

Choose your usage

Use only what you need

Start simply and activate only the features useful to your professional context.

Privacy by design

Keep control of your data

MyProID limits exposure, favors local resources and documents the processing actually used.

One stable linkLocal QRvCard