Privacy Notice
Last updated: 14 July 2026
Controller and contact
Christopher Bratt, Futur73 is the controller for account, marketplace, moderation, audit, and privacy-rights processing on Tignes Saison.
Privacy contact: [email protected]. DPO/contact-for-rights: No DPO has been designated.
Seasonal Workers can also export or delete their Worker Profile data from their account.
Data we process
We process account details, Worker Profile details, contact details, languages, job categories, availability, accommodation and workplace-reachability information, Work Authorisation Status, short introductions, Applications, CV files, optional Profile Photos, Employer Profiles, Jobs, transactional emails, file metadata, and audit records.
Account security also uses session data, which can include session tokens, IP addresses, user agents, verification tokens, and password-reset records.
CVs may contain extra information chosen by the Seasonal Worker. Employers and Platform Admins must not extract, rank, or filter on sensitive information that is not necessary for the hiring purpose.
Purposes and legal bases
Account access, Worker Profiles, Employer Profiles, Jobs, Applications, private file access, and transactional emails are processed to provide the service requested by users and, for Applications, to take pre-contractual recruitment steps requested by the Seasonal Worker.
Employer approval, job moderation, access logs, abuse prevention, security, confidentiality controls, and minimal operational history are processed for legitimate interests in running a safe recruitment marketplace.
The CV Directory is optional. A Seasonal Worker chooses whether to appear in it and can turn visibility off at any time. Privacy-rights handling and legally required records are processed to meet legal obligations.
Who can see the data
A Job Application shares the relevant Worker Profile, email, optional phone sharing, job-fit details, and the worker's current uploaded CV with the Employer for that Job. The CV Directory shares opt-in Worker Profiles and current uploaded CVs only with Approved Employers while visibility is active.
Platform Admins may access profile, application, file metadata, and audit data for support, deletion, moderation, employer approval, and compliance requests. Service providers process data only to run the service: Dokploy hosting, PostgreSQL database, private S3-compatible file storage, Resend transactional email.
Confidentiality and security
CVs and Profile Photos are stored as private files. CV access is limited to authorised hiring contexts, uses short-lived signed links, and is logged. Profile Photos stay private to the Seasonal Worker for now.
Approved Employers must use Worker Profile, contact, Application, CV Directory, and CV data only for genuine recruitment, must not bulk export it, and must keep it confidential.
Retention
Worker Profiles and Employer Profiles are kept while the account or hiring relationship is active. CV Directory visibility expires after 4 months unless renewed or turned off earlier.
The Worker Profile deletion workflow queues current private files for storage deletion, anonymises direct profile fields and Application free text, removes future hiring visibility and phone sharing, and keeps minimal Application and audit history for operational context. Failed storage deletion is retried and surfaced for operational action. Backup and object-storage lifecycle deletion follows deployment retention settings.
The scheduled retention cleanup removes Worker Profiles after 2 years without profile or Application activity, expires sessions and verification tokens, and removes audit history after 5 years. A shorter deletion request still applies. A limited, access-restricted archive may be kept longer only where needed for legal obligations or legal claims.
Rights
People whose data is processed may request access, rectification, deletion, restriction, portability, and objection where GDPR allows. Seasonal Workers may also withdraw CV Directory visibility at any time.
Requests should be answered within 1 month, with any lawful extension explained within that first month. You may also complain to the CNIL. Tignes Saison does not use automated hiring decisions or ranking. Approved Employers can use manual CV Directory filters for job-relevant fit signals.
Cookies and transfers
The beta uses only cookies required for account access, security, and remembering the selected language. It uses no advertising or cross-site tracking cookies. If audience measurement is added, it must meet CNIL consent-exemption conditions or collect user consent.
Non-EU/EEA transfers: Provider locations and transfer safeguards are reviewed before launch; where a provider transfers data outside the EU/EEA, the applicable provider DPA and Standard Contractual Clauses must apply.