Legal notices

This policy covers all processing carried out by OPPER, both as data controller — including the opper.io website and our commercial activities — and as data processor, within the framework of our SaaS solutions and outsourced services.

1. Purpose

OPPER attaches the utmost importance to protecting your privacy and complying with Regulation (EU) 2016/679 (“GDPR”). This policy clearly explains how we process your personal data when you browse our site and carry out transactions on it.

By using our site, you accept this policy. If you do not accept its terms, we invite you not to continue browsing. For any questions or to exercise your rights (see section 11), please contact our DPO at: dpo@opper.io.

2. Our activity and our role

OPPER is a publisher of media solutions. For over 35 years, we have supported media and Entertainment industry players in their digital transformation, working with B2B data, SaaS software, and outsourced services (subscription management, customer relations, invoicing, etc.).

Depending on the processing involved, OPPER acts in two capacities:

  • Data Controller: When OPPER itself determines the purposes and means of processing, for its own needs.
  • Data Processor: When OPPER processes data on behalf of a client (who remains the data controller). OPPER then acts on the client’s documented instructions, within the framework of a processing agreement compliant with Article 28 of the GDPR.


2.1. Processing carried out as data controller

  • Marketing of our services (order management, quotes, contracts, and invoicing).
  • Management of our customer, supplier, and partner relationships (B2B).
  • B2B commercial prospecting.
  • Sending our newsletters and marketing communications.
  • Recruitment of our candidates.
  • Management of our website, cookies, and security.


2.2. Processing carried out as data processor

For this processing, carried out on behalf of our clients, the legal basis is determined by the responsible client (most often the performance of the contract concluded with the data subject).

  • Provision of the SaaS service (platform access, account creation and management, execution of features).
  • Management of subscriptions and subscriber relations on behalf of the publisher (back-office, content access).
  • Routing and sending of newsletters and email campaigns on behalf of the client.


3. What data do we collect?

We may collect, directly from you, from third parties, or from sources accessible online, the following categories of data:

  • Identification data: last name, first name, phone number, postal or email address, content of your messages and, in the case of a subscription, proof of identity.
  • Browsing data: connection timestamp, IP address, technical information about your device (browser, operating system, device type), cookies and trackers.
  • Connection data: login credentials, password, and information required for authentication and access to your account.

Certain information, marked with an asterisk on our forms, is mandatory; without it, we will not be able to provide you with the relevant service.

4. Who is concerned?

This processing concerns visitors to our site, users of our platforms, and candidates for our job openings.

5. Why and for how long?

We process your data for specific purposes, each based on a legal basis and subject to a maximum retention period. These periods apply unless you request erasure or a legal obligation requires otherwise.

Purpose Legal basis Retention period
As data processor    
Provision of the SaaS service: platform access, account creation and management, execution of features Performance of a contract For the entire duration of the contractual relationship
Management of subscriptions and subscriber relations on behalf of the publisher Performance of a contract For the entire duration of the contractual relationship
As data controller    
Management of supplier, partner, and B2B customer relationships Contract Duration of the relationship + 2 years
Invoicing and bookkeeping Legal obligation 10 years (Art. L123-22 para. 2 of the French Commercial Code)
B2B commercial prospecting Legitimate interest 3 years after the last contact or until unsubscription (CNIL recommendation)
Recruitment of candidates Pre-contractual measures Successful candidate: duration of the relationship + 5 years. Unsuccessful candidate: no retention
Quote and contact requests Contract / Legitimate interest 5 years after the last interaction; quotes retained for 5 years after signature
Management of subscriptions, customer accounts, and newsletters Contract / Consent Duration of the subscription and applicable legal obligations
Site protection and anti-spam measures (reCAPTCHA) Legitimate interest Data collected by Google LLC, according to its own retention periods

We may also retain certain data to comply with our legal obligations (fighting fraud, money laundering, and terrorist financing, bookkeeping, site security) or to exercise our rights, as well as for statistical purposes.

6. Cookies and pixels

When you browse our site or open our emails, cookies and pixels (also called trackers) may be placed or read on your device. A cookie is a small file stored on your device; a pixel is an invisible image embedded in a page or email, used to measure viewing and interaction.

Depending on their purpose, we use the following categories:

Category Purpose Consent / legal basis
Strictly necessary Site operation and security: session, authentication, load balancing, anti-bot protection (reCAPTCHA) Legitimate interest
Functional / preferences Remembering your choices (language, display settings) Consent
Audience measurement Site traffic and usage statistics Consent
Marketing / advertising and pixels Personalization, measurement of our campaigns, and open/click pixels in our emails Consent
Third-party cookies Embedded content (YouTube) and reCAPTCHA, provided by Google LLC, which may result in a transfer outside the EU (see section 8) Consent

Our site uses Axeptio to manage users’ cookie preferences. No non-essential cookie is placed without their consent. To analyze traffic and improve our services, we use Matomo, a privacy-friendly web analytics solution. Matomo anonymizes IP addresses, does not transfer data outside the European Union, and uses it only for statistical purposes. Users can object to this audience measurement at any time via the Axeptio module.

Pixels in our emails

Our newsletters and marketing emails may contain pixels that allow us to know whether a message has been opened and which links have been clicked, in order to improve our communications. You can object to this at any time by unsubscribing via the link provided in each email.

7. Do we share your data?

Your data is transmitted to our internal departments and to organizers only when strictly necessary for the purposes described. We may also share it with our service providers:

These providers only receive the data necessary for their assignment and contractually commit to preserving its confidentiality and security, without using it for other purposes. Your data may also be transmitted to the competent authorities to comply with our legal obligations.

Your data is never sold.

8. Is your data transferred outside the EU?

OPPER strives to keep your data in France or within the European Economic Area (EEA). However, some data may be transferred outside the EU, notably via the reCAPTCHA and YouTube services provided by Google LLC (United States).

Any transfer outside the EU is regulated: either to a country offering an adequate level of protection, through standard contractual clauses recognized by the European Commission, or through binding corporate rules. The relationship with Google is governed by a processing agreement and by these standard contractual clauses.

9. How do we secure your data?

We implement appropriate technical and organizational measures to protect your data against any loss, destruction, alteration, or unauthorized disclosure, including:

  • Data access limited to authorized staff;
  • Restriction of administrator accounts;
  • Encryption of communications (SSL protocol);
  • Regular backups, antivirus, and firewalls;
  • Contractual guarantees with our service providers and impact assessments.

The effectiveness of these measures is regularly reassessed to maintain a high level of security.

10. Retention period

We retain your data only for as long as necessary for the purpose pursued (see section 5), based on our business needs, contractual requirements, our legal obligations, and the recommendations of supervisory authorities.

11. What are your rights?

The GDPR grants you several rights over your personal data. You may at any time access the data we hold about you and obtain a copy of it, have it corrected if it is inaccurate or incomplete, or request its erasure, except where we have a legitimate reason to retain it.

You may also request restriction of processing, object to it on grounds relating to your particular situation, or withdraw your consent at any time where the processing is based on it.

You also have a right to data portability, allowing you to retrieve your data in a reusable format, the right not to be subject to a decision based solely on automated processing, and the right to set guidelines for what happens to your data after your death.

OPPER has implemented a procedure for handling these requests, ensuring transparent information and compliance with legal requirements.

To exercise your rights, contact the Data Protection Officer (DPO): dpo@opper.io.

By mail: OPPER – 20, rue Rouget de Lisle, 92130 Issy-les-Moulineaux.

Your request has been received.

THANKS !