MisterBridge.
Privacy Policy
Version dated 3 October 2026
1. Data controller
The data controller is BIZNESSMATCH FRANCE, 3 bis rue de l’Isère, 38120 Saint-Égrève, France. For any question relating to your data, contact the Data Protection Officer (DPO) at data@misterbridge.com.
2. Data collected
We collect the following categories of data:
- Identification data: last name, first name, professional email address, phone number (optional), profile photo (optional), password (encrypted).
- Company data: company name, SIRET, registered office address and contact details, business description, turnover, headcount, verification documents.
- Connection data: IP address, device type, browser, login date/time, approximate location.
- Payment data: Stripe customer ID, transaction history, invoices (bank details are managed by Stripe).
- Usage data: messages exchanged, reviews, search history, profiles viewed.
- Club and event data: registrations and applications, tickets (including the name and e-mail address of guests to whom you pass on a ticket) and QR code, attendance at the event (entrance check-in), orders and refunds, club membership and, where applicable, membership of a club group, appointments between participants, reviews, and event photos and videos.
3. Purposes and legal bases
Your data is processed for the following purposes and on the following legal bases:
- Account creation and management, authentication, messaging, geolocation of services, payments — performance of the contract (Art. 6.1.b GDPR).
- Invoicing and accounting record-keeping — legal obligation (Art. 6.1.c GDPR).
- Security, fraud prevention, connection logs — legitimate interest (Art. 6.1.f GDPR).
- Audience measurement, newsletter, SMS notifications — consent (Art. 6.1.a GDPR).
- Introductions and profile enrichment through artificial intelligence: company descriptions and skills are processed by our processor OpenAI to compute recommendations — performance of the contract. This processing does not constitute automated decision-making within the meaning of Article 22 GDPR: the results are advisory and you remain the decision-maker. The systems in use are detailed in the artificial intelligence transparency document.
- Visibility statistics: when you view a company's profile, or when its profile appears in one of your searches, that company can see your name, your profile picture, your company's name and logo, your city, the relevant trade and the event date, so that it can contact you back. Access to this information is reserved to companies holding a plan that includes it; others see a masked notice. This processing is based on the legitimate interest of registered companies in identifying their prospects (Art. 6.1.f GDPR); you may object by writing to the Data Protection Officer.
- Registration for events, ticket issuance, access control and attendance tracking, handling of applications where a club makes registration subject to its approval, management of orders and refunds, networking between participants, event albums and reviews — performance of the contract (art. 6.1.b GDPR).
- Automatic registration to group events: when a club publishes a free event intended for one of its groups, the manager of each member company of that group is registered automatically and informed by e-mail. The group is merely an internal organisational label within the club, with no effect on your access rights. This processing is based on the legitimate interest of the club and its members in bringing together the members of the same group (art. 6.1.f GDPR); you may object to it by unregistering from the event up to 24 hours before it starts, or by writing to the data protection officer.
4. Recipients and subprocessors
Your data is accessible to authorised staff of the Publisher and to the following subprocessors:
- Subprocessors established within the European Union: Scaleway (hosting, France), PostHog (audience measurement, EU), Sentry (technical monitoring, EU), BulkGate (SMS, EU).
- Subprocessor established in Switzerland, a country recognised by the European Commission as ensuring an adequate level of personal data protection: Infomaniak (email hosting, Switzerland). The transfer relies on that adequacy decision, without recourse to Standard Contractual Clauses.
- Subprocessors outside the EU (transfers governed by the European Commission's Standard Contractual Clauses): Stripe (payments, USA), SendGrid/Twilio (emails, USA), Google — Analytics, Maps and Firebase Cloud Messaging (audience measurement, mapping and mobile app push notifications, USA), OpenAI (AI processing, USA), Cloudflare (security and CDN, USA).
- Organisers and clubs: the organising club and its team receive the registration, application and attendance data needed to run the event. Other participants may see your name, company and profile in the participant list, unless the club restricts it to its members or you have chosen not to appear in it.
5. Retention periods
- User account: until it is deleted, or 2 years after the last sign-in. An email warns you 30 days and then 7 days beforehand. The account is then anonymised; invoices and accounting records are kept for 10 years.
- Invoices and accounting data: 10 years (legal obligation).
- Connection logs: 12 months.
- Consent cookie: 13 months.
- Event registration, ticketing and attendance data: until the account is deleted; related payment records follow the period applicable to invoices. Event-change alert delivery log: 12 months.
6. Your rights
In accordance with the GDPR, you have the rights of access, rectification, erasure, portability, objection and restriction. You can exercise these rights from your settings or by writing to data@misterbridge.com.
For events, if you were registered automatically, you may unregister from your account area up to 24 hours before the start; you may also request the removal of a photo or video of you, or hide your presence from the participant list.
You may also lodge a complaint with the CNIL (www.cnil.fr).
7. Security
We implement technical and organisational measures: password encryption, HTTPS, anti-bot protection (Cloudflare Turnstile), antivirus scanning of files, token-based authentication and role-based access management.
8. Changes
This policy may be updated. Any substantial change will be brought to your attention.