Last updated: May 13, 2026

Privacy Policy

This privacy policy (hereinafter the "Policy") describes how GROUPE YDYLE (hereinafter "Eskimoz," "we") collects, uses, and protects the personal data of users of the Eskimoz Community platform (hereinafter the "Service"), accessible via the website https://eskimoz.community and the associated browser extension.

This Policy complies with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 ("GDPR") and the amended French Data Protection Act (Loi Informatique et Libertés) of 6 January 1978.

1. Data Controller

GROUPE YDYLEa simplified joint-stock company (SAS) with share capital of €26,000

RCS Nanterre 528 338 494

SIRET (siège) : 528 338 494 00024

N° TVA : FR 89 528 338 494

Headquarter : 19 rue du Dôme, 92100 Boulogne-Billancourt

Phone : +33 1 84 88 41 17

Email : contact@eskimoz.fr

Publication Director : Andrea Bensaid.

For any questions regarding this Policy or to exercise your rights, you may write to contact@eskimoz.fr.

2. Data Collected

We only collect the data strictly necessary for the operation of the Service. Three categories of data are processed:

2.1 Account Data

  • Email address (login ID)
  • Name and surname
  • Password (never stored in plain text — hashed via bcrypt)
  • Avatar (optional)
  • Role within your organization (admin / user)
  • Preferences (language, time zone, notification settings)

2.2 LinkedIn Data (via the browser extension)

The Eskimoz Community Chrome extension reads certain data from your LinkedIn session to enable the Service's features. Specifically:

  • Reading of the JSESSIONID cookie from linkedin.com (used as a Voyager CSRF token — not stored, used only during the request)
  • LinkedIn ID (URN), public profile URL, full name, profile photo
  • Published posts (content, LinkedIn ID, timestamp, media)
  • Engagement statistics (impressions, likes, comments, shares)
  • List of your LinkedIn connections (count + identifiers)
  • Number of followers
  • LinkedIn OAuth tokens (encrypted at rest via pgsodium in the database)
  • Technical device fingerprint, used for multi-device management of the extension
  • Extension heartbeats (timestamp, extension version, status)

The extension reads the li_at cookie from linkedin.com solely to detect whether an active LinkedIn session exists in the browser. This value is never transmitted to our servers or stored — it is read on the fly and immediately discarded. The extension does not read your private messages and does not store any LinkedIn data in the browser outside of the temporary CSRF cache (≤ 5 min).

To enable publishing and engagement features, the extension also captures certain technical headers (CSRF token, tracking identifiers) from outgoing requests to LinkedIn's internal Voyager API. These headers are necessary to authenticate API calls made on your behalf; they do not contain personal content and are used only during the active session.

2.3 Prospecting Data

  • Public LinkedIn profiles that have interacted with your posts (name, URN, job title, company, industry) — collected from public LinkedIn pages
  • Direct messages sent from the Service to prospects (content, timestamp, status, conversation ID)
  • Personal preferences (favorites, hidden items, filters)

2.4 Technical and Log Data

  • Server logs (IP address, user agent, timestamp)
  • Audit log (actions performed within the Service, for security and traceability purposes)
  • Technical session cookies (see Section 6)

3. Purposes and Legal Bases

Purposes Legal Bases Categories
Creation and management of the user account Performance of contract (Art. 6(1)(b) GDPR) 2.1, 2.4
Automated publishing on LinkedIn on behalf of the user Performance of contract (Art. 6(1)(b) 2.1, 2.2
Engagement measurement, dashboards, ranking Performance of contract 2.2
Identification and management of prospects Legitimate interest of the Client (B2B commercial prospecting — Art. 6(1)(f)) 2.3
Security, abuse prevention, audit Legitimate interest (Art. 6(1)(f)) 2.4
Legal obligations (retention, official requests) Legal obligation (Art. 6(1)(c)) 2.1, 2.4

4. Recipients and Data Processors

Your data is accessible to authorized teams at Groupe Ydyle and to our technical data processors, under contractual commitments compliant with Articles 28 and 32 of the GDPR:

  • Supabase (Supabase Inc., Singapore; EU infrastructure — Frankfurt, Germany) — hosting of the database, authentication, and storage
  • LinkedIn (LinkedIn Ireland Unlimited Company, Ireland / LinkedIn Corp., United States) — official API for publishing
  • Resend (Resend Inc., United States) — sending of transactional emails (invitations, notifications)
  • GIPHY (Giphy, Inc., United States) — animated GIF search within messaging (API request, no personal data transmitted)

No data is sold or rented to third parties for commercial purposes.

5. Transfers Outside the European Union

Some data processors (LinkedIn, GIPHY, Resend) are located in the United States. These transfers are governed by the European Commission's Standard Contractual Clauses (SCCs) (Decision 2021/914) or, where applicable, by the EU-U.S. Data Privacy Framework for certified providers. The current list of certifications can be found at dataprivacyframework.gov.

6. Cookies and Trackers

The Service only uses cookies strictly necessary for its operation (Supabase authentication session, language preference, theme). No third-party audience measurement cookies or advertising cookies are set. The browser extension does not set cookies on the sites you visit.

7. Retention Periods

  • Active user account : for the duration of the contractual relationship
  • Deactivated / deleted account : 30-day grace period, followed by permanent deletion (Clients may be subject to longer retention periods where required for contractual or legal reasons)
  • LinkedIn OAuth tokens : deleted immediately upon revocation or disconnection
  • Audit log : 3 years (legal traceability obligation)
  • Technical logs : 12 months maximum (CNIL guidelines)
  • Prospecting data : for as long as you remain an active user, or until a deletion request is made

8. Security

We implement appropriate technical and organizational measures to protect your data against loss, theft, alteration, and unauthorized access:

  • End-to-end TLS 1.3 encryption for all network communications
  • Encryption at rest of sensitive data (OAuth tokens) via pgsodium
  • Passwords stored as bcrypt hashes (never in plain text)
  • Multi-factor authentication (TOTP MFA) available and required for administrator accounts
  • Row Level Security policies in Supabase to partition data between accounts
  • Immutable audit log of all sensitive actions
  • Data access restricted to authorized personnel

9. Your Rights

In accordance with Articles 15 to 22 of the GDPR, you have the following rights over your data:

  • Right of access — to obtain a copy of your data
  • Right to rectification — to correct inaccurate information
  • Right to erasure ("right to be forgotten") — to request the deletion of your data
  • Right to restriction of processing
  • Right to data portability — to receive your data in a structured, machine-readable format (JSON)
  • Right to object to processing based on legitimate interest
  • Right to withdraw your consent at any time, where processing is based on it
  • Right to set directives regarding the fate of your data after your death

To exercise these rights, please write to contact@eskimoz.fr specifying your request and enclosing a copy of an identity document if we are unable to authenticate you by other means. We will respond withinone month,extendable by two months for complex requests.

You also have the right to lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07 — https://www.cnil.fr/fr/plaintes.

10. Minors

The Service is not intended for minors. We do not knowingly collect personal data from anyone under the age of 18. If you become aware that an account has been created by a minor, please report it to contact@eskimoz.fr and it will be deleted immediately

11. Changes to this Policy

We may update this Policy from time to time, in particular to reflect technical, legal or regulatory changes. The date of the last update is shown at the top of this page. If we make material changes, users will be notified by email or through an in-app notification at least 30 days before they take effect.

12. Contact

For any questions regarding this Policy or to exercise your rights, you may write to

Email : contact@eskimoz.fr

Website: https://www.eskimoz.fr/contact/

By post: Groupe Ydyle, 19 rue du Dôme, 92100 Boulogne-Billancourt, France