Article 1 — Data controller
The data controller for your personal data is OneMICE SAS, with its registered office at 22 rue du 8 mai 1945, 95340, Persan — France (hereinafter “OneMICE”, “we”). OneMICE is registered with the Pontoise Trade and Companies Register under number 106 495 922. Data Protection Officer (DPO): privacy@onemice.com — OneMICE SAS, 22 rue du 8 mai 1945, 95340, Persan. Any request relating to your personal data may be sent directly to our DPO.
Article 2 — Data collected
As part of the use of our site and platform, OneMICE may collect the following categories of data: identification data (first name, last name, email address, phone number); professional data (company, role, department); connection and usage data (IP addresses, login logs, pages visited, session duration, actions taken on the platform); contractual data (order history, booked events, amounts, suppliers contacted). We do not collect any sensitive data within the meaning of Article 9 of the GDPR (racial origin, religious beliefs, health data, etc.). Data relating to minors is not intentionally collected — our platform is intended exclusively for professionals.
Article 3 — Purposes and legal bases for processing
Your data is processed for the following purposes, on the legal bases indicated: — Performance of the contract: managing your account, access to the platform, processing your requests and event bookings, invoicing and payment. — Legitimate interest: securing the platform, fraud prevention, improving our services, anonymized statistical usage analysis. — Consent: sending marketing communications and newsletters (explicit opt-in, withdrawable at any time). — Legal obligation: retaining accounting and tax data in accordance with applicable legal provisions. OneMICE carries out no profiling for the purpose of automated decision-making that produces legal effects or significantly affects the individuals concerned.
Article 4 — Retention period
Data is retained for the period strictly necessary for the purposes for which it was collected, in accordance with applicable legal and regulatory obligations. For guidance: active account data is retained for the entire duration of the contractual relationship; inactive customer data is deleted or anonymized within 3 years of the last contact; billing data is retained for 10 years in accordance with accounting obligations; connection logs are retained for 12 months in accordance with French regulations. At the end of these periods, data is securely deleted or irreversibly anonymized. You may request early deletion of your data under the conditions set out in Article 7.
Article 5 — Data sharing
OneMICE neither sells nor rents your data to third parties. Your data may be shared in the following cases: technical service providers acting as data processors (AWS hosting, audience analytics tools, customer support) bound by GDPR-compliant data processing agreements; partner event service providers, solely for the purpose of managing your booking requests and with your prior consent; competent authorities, in the event of a legal obligation, court order, or the need to protect our rights. Each client instance is technically isolated. One client’s data is never accessible to another client, nor used to train third-party artificial intelligence models.
Article 6 — Data transfers outside the European Union
OneMICE’s infrastructure is hosted in the AWS eu-west-1 region (Ireland), within the European Union. Where certain subprocessors are established outside the EU, OneMICE ensures that transfers are governed by appropriate safeguards: European Commission Standard Contractual Clauses (SCCs), adequacy decisions, or equivalent mechanisms recognized by the GDPR. The list of subprocessors involving transfers outside the EU is available on request from our DPO: contact@onemice.com
Article 7 — Data security
OneMICE implements appropriate technical and organizational measures to protect your data against unauthorized access, loss, destruction, or accidental disclosure. These measures include in particular: encryption of data in transit (TLS 1.3) and at rest (AES-256); strong authentication (MFA) for all administrator access; regular security audits and annual penetration tests; ISO/IEC 27001 certification. In the event of a data breach likely to result in a risk to your rights and freedoms, OneMICE will notify the CNIL within 72 hours in accordance with Article 33 of the GDPR, and will inform you as soon as possible if the risk is high.
Article 8 — Your rights
In accordance with the GDPR and the French Data Protection Act, you have the following rights regarding your personal data: — Right of access: obtain confirmation that data concerning you is being processed and receive a copy of it. — Right to rectification: correct inaccurate or incomplete data. — Right to erasure: request deletion of your data in the cases provided for by law. — Right to restriction: request the temporary suspension of processing. — Right to portability: receive your data in a structured, readable format. — Right to object: object to certain processing based on legitimate interest. To exercise these rights, contact our DPO: contact@onemice.com. We will respond within one month (extendable by two months for complex requests). If you are not satisfied with our response, you may file a complaint with the CNIL (www.cnil.fr) or the competent supervisory authority in your member state.
Article 9 — Cookies and trackers
The website onemice.com uses cookies and trackers. On your first visit, a banner lets you set your preferences. Strictly necessary cookies (exempt from consent): session, authentication, CSRF security, language preferences. Analytics cookies (subject to consent): anonymized audience measurement (Plausible Analytics, no transfer outside the EU, no data cross-referencing). Marketing cookies (subject to consent): retargeting, LinkedIn Insight Tag, only if you have accepted them. You can change your preferences at any time via the “Manage my cookies” link at the bottom of the page, or in your browser settings. Your consent remains valid for 6 months.
Article 10 — Contact, complaints, and updates
For any question relating to this policy or the exercise of your rights, contact our Data Protection Officer: DPO OneMICE SAS — contact@onemice.com — 22 rue du 8 mai 1945 – 95340 – Persan
To file a complaint with the French supervisory authority: CNIL — 3 Place de Fontenoy, 75007 Paris — www.cnil.fr. This privacy policy may be updated at any time to reflect legislative, regulatory, or practice changes. Any substantial change will be notified to you by email or via an information banner on the site, at least 30 days before it takes effect.
Version in effect: June 2026. Last updated: June 11, 2026. OneMICE SAS — contact@onemice.com