Trust · Legal · Security · Compliance

Trust as infrastructure.

The RDMC Trust Center centralizes the contractual, operational and regulatory commitments related to our digital services, security, data protection, artificial intelligence and sensitive technologies.

Reference document

Privacy policy

Version 2.0 — effective as of 01/04/2026

RDMC processes personal data of visitors, prospects, customers, partners, suppliers, candidates and users of its services.

Data controller

EntityRDMC SAS
Address1 rue de la Destinée, 95800 Cergy, France
SIREN880 905 088
SIRET880 905 088 00014
VAT numberFR37 880 905 088
D‑U‑N‑S273969130
Contactprivacy@rdmc.fr

Data processed

  • identity and professional contact details;
  • role, company and business relationship;
  • requests, tickets and correspondence;
  • contractual, billing and payment data;
  • technical logs, IP address, device and timestamp;
  • application / recruitment data;
  • data entrusted by customers when RDMC acts as a processor.

Purposes and legal bases

PurposeLegal basis
Requests and proposalsPre-contractual steps and legitimate interest
Contracts and servicesPerformance of the contract
BillingLegal obligation
SecurityContract and legitimate interest
Optional cookiesConsent

Data retention periods

RDMC applies the principle of storage limitation. Personal data is retained for no longer than is necessary for the purposes for which it was collected and processed.

Some data may nevertheless be placed in intermediate archiving where a legal or regulatory obligation so requires, or where retention is necessary for the establishment, exercise or defence of legal claims.

Applicable periods

Data categoryRetention period
Contact and information requestsFor as long as needed to handle the request, then for up to 3 years from the last contact where a business relationship may continue.
Prospects and commercial relationshipsFor up to 3 years from the last contact with the prospect, unless the data subject objects or a specific obligation justifies a different period.
Customer and contractual dataFor the entire duration of the contractual relationship, then archiving of necessary data for the applicable legal retention or limitation periods.
Invoices, orders and accounting records10 years from the close of the relevant financial year, in accordance with applicable legal obligations.
Support tickets and assistance requestsFor as long as needed to handle and follow up the request, then for the duration of the contractual relationship. Evidence required to establish proof or to defend RDMC’s rights may then be placed in intermediate archiving for the applicable limitation periods.
Technical logs, security logs and connection dataA maximum of 12 months from recording, unless a legal or regulatory obligation requires a different period.
Recruitment / application dataFor the duration of the recruitment process and, where retention is justified, for up to 2 years after the last contact with the candidate, unless an erasure request or applicable objection applies.
Optional cookies and trackersAccording to the period applicable to the tracker concerned and in line with the rules set out in the Cookie and consent policy.
Data processed on behalf of customersFor the period defined by the customer, acting as controller, in accordance with the contract and its documented instructions.
Data relating to an incident, dispute or litigationFor as long as needed to handle the incident or dispute and, where necessary, until the applicable limitation periods and remedies expire.
Technical logging
12 months maximum

Technical logs generated by the systems, applications, servers, hosting infrastructure, network equipment and security devices operated by RDMC are retained for a maximum of 12 months from recording.

They may notably include IP addresses, timestamps, technical identifiers, authentication events, access and connection traces, as well as system, network, application or security events.

Purposes of logging

  • information systems security;
  • infrastructure and service monitoring;
  • detection, analysis and handling of incidents;
  • diagnosis and remediation of malfunctions;
  • traceability of access and operations;
  • detection and prevention of unauthorised access, abuse and attack attempts;
  • maintaining operational (MCO) and security (MCS) conditions.

At the end of the retention period, the relevant logs are deleted or anonymised, unless a legal or regulatory obligation, judicial proceedings, a request from a competent authority, or the need to establish, exercise or defend a legal claim justifies retention for an additional period.

Technical connection data subject to a specific legal or regulatory regime, in particular in the context of electronic communications activities, may be subject to distinct retention periods and arrangements.

Data processed on behalf of our customers

Where RDMC acts as a processor within the meaning of the GDPR, the retention period for data processed on behalf of the customer is determined by the customer, acting as controller.

RDMC processes and retains such data in accordance with the customer’s documented instructions, the applicable contractual terms and the legal and regulatory obligations to which RDMC is subject.

At the end of the service or upon the customer’s instruction, the data is, depending on the applicable contractual terms, returned, deleted or anonymised, subject to any legal obligations requiring retention.

Deletion, anonymisation and archiving

At the end of their active retention period, data is, depending on its nature and applicable obligations:

  • securely deleted;
  • irreversibly anonymised; or
  • placed in intermediate archiving, with access limited to authorised persons only, where a legal or regulatory obligation or the defence of RDMC’s rights justifies retention.

Archived data is no longer used for the operational purposes that justified its initial collection.

Data that has been effectively and irreversibly anonymised so that it no longer allows a natural person to be identified directly or indirectly may be retained for statistical, technical, security or service-improvement purposes.

Criteria for determining retention periods

Where no specific period is imposed by law or regulation, RDMC determines the appropriate retention period taking into account in particular:

  • the purpose for which the data was collected;
  • the duration of the contractual or commercial relationship;
  • the nature and sensitivity of the data;
  • applicable legal and regulatory obligations;
  • limitation periods;
  • security and traceability requirements;
  • needs related to the prevention, detection and investigation of incidents;
  • any need to establish, exercise or defend legal claims.

RDMC periodically reassesses the retention periods applied to ensure they remain necessary, proportionate and suited to the purposes pursued.

Hosting and infrastructure

This website is hosted and operated by RDMC SAS, which provides administration, operational maintenance and supervision of the hosting infrastructure.

The technical infrastructure used by RDMC relies on computing resources located in OVHcloud data centres in France. OVHcloud acts as an infrastructure and data centre provider.

Recipients and transfers

Data is accessible to authorised RDMC personnel and to necessary service providers. Transfers outside the European Economic Area are framed by a GDPR-recognised mechanism.

Rights

You may exercise the rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent where those rights apply to the processing concerned.

Requests should be sent to privacy@rdmc.fr. You may also lodge a complaint with the CNIL.