Back to homepage Data protection

Privacy Policy

Last updated 18 June 2026
Compliance GDPR, Regulation (EU) 2016/679

Oxysign Group attaches the greatest importance to protecting your personal data. This policy sets out transparently what data we collect, why, how long we keep it, who it is shared with, and the rights available to you. It applies to Oxysign Group website and to the processing carried out by the Group and its five brands: Oxysign, Semios, Interimages, C2K XXL and Toit de Paris.

01

Data controller

The controller of the personal data processed through this site is Oxysign Group. For any question regarding your personal data:

Registered name Oxysign Group
Registered office address 518 avenue de Jouques, ZI Les Paluds II, 13400 Aubagne, France
SIRET number to be provided
02

Data we collect

We only collect data that is strictly necessary for the purposes described below, in accordance with the data minimization principle.

  • Identification and contact data: company, first name, email address and telephone number, submitted through our contact form.
  • Content of your enquiry: the subject and message you send us.
  • Technical data: strictly necessary for the operation and security of the site (see the Cookies section).

Fields marked with an asterisk in our forms are mandatory; all others are optional. We do not collect any "sensitive" data (health, opinions and the like).

03

Purposes & legal bases

Each processing operation rests on a specific legal basis within the meaning of Article 6 of the GDPR:

Responding to your enquiries
Handling messages sent through the contact form.
Pre-contractual steps
Client relationship
Tracking correspondence, quotations and projects with clients and prospects.
Legitimate interest
Site security
Fraud prevention and correct technical operation.
Legitimate interest
Legal obligations
Retention of certain data for accounting and statutory purposes.
Legal obligation
04

Data recipients

Your data is processed by authorized teams within Groupe Oxysign and, where relevant, within the brand concerned by your enquiry. It is never disclosed or sold to third parties for commercial purposes.

Our only technical sub-processor is Microsoft, which hosts our email and collaboration tools. Your data remains inside the Group's own Microsoft tenant and is not passed on to any third-party service.

05

Hosting & location

Your data is hosted within the European Union, on infrastructure located in France. No transfer of your data outside the European Union takes place. Should such a transfer become necessary, it would be covered by the safeguards set out in the GDPR (European Commission standard contractual clauses).

06

Retention periods

Contact form enquiries (prospects) 3 years
Client relationship data Term of the relationship + 3 years
Accounting and contractual records 10 years (statutory requirement)
Strictly necessary cookies Session only

At the end of these periods, your data is securely deleted or anonymized.

07

Your rights

Under the GDPR, you have the following rights over your personal data at any time:

Right of access
Obtain confirmation that we hold data about you, and a copy of it.
Right to rectification
Correct or complete inaccurate or incomplete data.
Right to erasure
Request deletion of your data, subject to our legal obligations.
Right to restriction of processing
Request that the processing of your data be temporarily suspended.
Right to data portability
Receive your data in a structured, machine-readable format.
Right to object
Object, on legitimate grounds, to a given processing of your data.

To exercise these rights, write to us at contact@oxysign-group.com stating the purpose of your request. We may ask for proof of identity in the event of reasonable doubt. We reply within one month of receiving your request.

08

Cookies & trackers

This site uses only cookies that are strictly necessary for its operation and security. These cookies are exempt from consent under CNIL guidelines. No third-party advertising or analytics tracker is set without your prior agreement.

If non-essential cookies were ever added, your consent would be collected first, and you could withdraw it at any time. You can also configure your browser to refuse cookies.

09

Data security

We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure or destruction: encryption in transit, access control, hosting in France and restricted authorization for the staff who handle your data.

10

Complaint to the CNIL

If, having contacted us, you consider that your rights have not been respected, you may lodge a complaint with the French data protection authority (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or online at www.cnil.fr.

11

Changes to this policy

This policy may change to reflect regulatory developments or changes in our practices. Any substantial change will be flagged on this page, which shows the date it was last updated at the top.

A question about your data?
Our team will reply within one month.
Contact us