Privacy Policy
Last updated: April 28, 2026
Preamble
This privacy policy describes how Captive SAS, a company registered with the Paris Trade and Companies Register under number 103 735 726, with its registered office at 6 rue d'Armaillé, 75017 Paris, France (hereinafter "Captive", "we"), collects, uses, stores, and transmits personal data in the course of its activities.
It applies to:
- the website getcaptive.ai;
- applications accessible from the getcaptive.ai domain;
- data collection forms distributed through advertising campaigns on social networks, landing pages, or third-party forms operated on behalf of our clients;
collectively referred to as "the Services".
Captive operates as a growth marketing agency covering two complementary intervention models:
- Management of its Clients' advertising accounts under contractual mandate (Google Ads, Meta Ads, LinkedIn Ads, TikTok Ads, etc.), including campaign creation, delivery, optimization, and reporting through the official APIs of these platforms;
- Design and execution of lead generation campaigns on behalf of its Clients, in various sectors including B2B SaaS, recruitment, real estate, training, business and consumer services, including the collection, qualification, and transmission of prospect data.
1. Data controller and roles of the parties
1.1 During collection and processing of prospect data
Captive acts as data controller within the meaning of Regulation (EU) 2016/679 ("GDPR") for the following operations:
- design and delivery of advertising campaigns;
- collection of data through forms (social networks, landing pages, third-party forms);
- storage, enrichment, and qualification of prospects;
- sending follow-up communications (SMS, email) as part of the matching process.
1.2 Upon transmission to the client
Once data is transmitted to the professional client (hereinafter the "Client"), the Client becomes an independent data controller for all processing it carries out on this data (commercial exploitation, follow-ups, CRM integration, etc.). The Client undertakes, under its contract with Captive, to process the data in accordance with applicable regulations.
1.3 Platform users
Captive is the data controller for the data of users of its applications (recruiters, administrators, staff of its Clients).
2. Data collected
2.1 Prospects (people responding to a campaign)
Depending on the campaign and the Client's sector, all or part of the following data may be collected:
- Identity: first name, last name, title/gender
- Contact details: email address, phone number, postal address (street, postal code, city, country)
- Professional profile (recruitment campaigns): LinkedIn URL, curriculum vitae (CV)
- Questionnaire responses: qualification questions customized for each campaign (professional situation, needs, preferences, availability, etc.)
- Free-text message and any information the prospect chooses to share
- Tracking data: campaign source (UTM), timestamp, origin platform
Data collected varies from one campaign to another. Only data strictly necessary for the purpose of each campaign is requested.
2.2 Platform users (recruiters, administrators)
- Identity: first name, last name
- Contact details: email address, phone number
- Connection data: IP address, user agent, login timestamps
- Role and affiliated organization
2.3 Site visitors
- Browsing data: IP address, pages visited, timestamps
- Strictly necessary technical cookies for site operation
3. Purposes, legal bases, and retention periods
| Purpose | Legal basis | Data | Retention |
|---|---|---|---|
| Collection and qualification of prospects on behalf of our Clients | Prospect's consent (form) | Prospect data (§ 2.1) | 24 months from collection or last interaction |
| Sending follow-up communications (SMS, email) | Consent | First name, phone, email | Duration of the relationship, withdrawal of consent, or 24 months max |
| Transmission of data to the Client | Consent (collected at the time of collection) | Prospect data (§ 2.1) | Transmission completed; retention by Captive per the period above |
| Application management (recruitment campaigns) | Legitimate interest | Prospect data (§ 2.1) | 24 months from last interaction |
| Sending application status notifications | Legitimate interest | First name, phone, email | Duration of the recruitment process |
| Electronic commercial prospecting | Consent | Email, phone | Until withdrawal of consent or 24 months without interaction |
| Management of user accounts and authentication | Contractual performance | User data (§ 2.2) | Duration of the contract + 12 months |
| Service security | Legitimate interest | IP, user agent, logs | 12 months |
| Statistics and performance measurement | Legitimate interest | Aggregated and anonymized data | No limit (anonymous data) |
| Legal and accounting obligations | Legal obligation | Billing data | 10 years |
Upon expiration of the indicated periods, data is irreversibly deleted or anonymized.
4. Collection channels
Prospect data is collected through the following channels:
- Forms integrated into social networks: Meta (Facebook, Instagram), TikTok, LinkedIn, Snapchat, and any other advertising platform used to deliver campaigns.
- Landing pages: destination pages hosted by Captive or its Clients, accessible via advertising links.
- Third-party forms: online form tools (Typeform, Google Forms, etc.) configured for specific campaigns.
In all cases, the prospect is informed at the time of collection of the identity of the data controller, the purpose of processing, and their rights, in accordance with Articles 12 and 13 of the GDPR.
5. Data recipients
5.1 Our professional Clients
Prospect data is transmitted to the Client on whose behalf the campaign was run. Transmission is carried out through one or more of the following means: access to our platform (dashboard), API integration, push to the Client's CRM, secure email delivery.
The Client becomes the data controller upon receipt of the data and contractually undertakes to process it in accordance with the GDPR.
5.2 Our technical subprocessors
| Subprocessor | Role | Location |
|---|---|---|
| Hetzner Online GmbH | Server and database hosting | Nuremberg, Germany (EU) |
| Cloudflare, Inc. | CDN, DDoS protection, DNS, file storage (R2) | EU / global network (standard contractual clauses) |
| Meta Platforms Ireland Ltd | Ad delivery, application forms | Ireland (EU) |
| Brevo (Sendinblue) | Sending follow-up SMS and emails | France (EU) |
| Anthropic | AI-powered ad content generation | United States (standard contractual clauses) |
| Google LLC / Google Ireland Ltd | Advertising platform (Google Ads), campaign management API (Google Ads API), audience measurement (Google Analytics, where applicable) | Ireland (EU) / United States (standard contractual clauses) |
This list may evolve. Subprocessors are selected for their data protection guarantees and are bound by contractual commitments compliant with Article 28 of the GDPR.
5.3 Third-party advertising platforms
As part of campaign delivery, form data may transit through the servers of the relevant advertising platforms (Meta, TikTok, LinkedIn, etc.), which act as joint or independent data controllers depending on the case, in accordance with their own privacy policies.
5.4 Competent authorities
Data may be disclosed upon judicial request or in compliance with a legal obligation.
5.5 Google Ads and Google Ads API
Captive uses Google Ads as well as the Google Ads API to manage, optimize, and report on advertising campaigns delivered on behalf of its Clients on the Google Ads accounts they have entrusted to it. The Clients' Google Ads accounts are linked to Captive's manager account (MCC) under an explicit contractual mandate that can be revoked by the Client at any time.
Within this scope, Captive accesses:
- campaign structures (ad groups, keywords, ads, audiences);
- performance statistics (impressions, clicks, cost, conversions) and aggregated audience reports;
- conversion data reported by the Client (typically aggregated or via technical identifiers such as click IDs).
No personal prospect data (name, email, phone, etc.) collected by Captive in the course of its lead generation activity is shared with Google beyond what is strictly necessary for ad delivery. Where applicable, the upload of hashed audience lists (Customer Match) or the transmission of offline conversions is performed only after obtaining the prospect's prior consent and in accordance with Google's policies.
Captive's use of the Google Ads API is governed by the Google Ads API Terms & Required Minimum Functionality and by Google's privacy policy: policies.google.com/privacy.
We never sell your personal data to third parties.
6. Transfers outside the European Union
Our data is primarily hosted in Germany (Hetzner, Nuremberg) and France. Some subprocessors (Cloudflare, Anthropic, Google) may process data outside the European Union. In such cases, appropriate safeguards are in place in accordance with Chapter V of the GDPR: standard contractual clauses adopted by the European Commission or adequacy decisions.
7. Data security
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption of communications (TLS/SSL)
- Encryption of sensitive data at rest in the database
- Centralized authentication with a strong password policy (minimum length, complexity, anti-brute-force protection)
- Separation of database access roles (least-privilege principle)
- Daily backups with automatic rotation
- Access logging and intrusion detection
- Application and network firewall
- Tenant-level data isolation between Clients
8. Use of artificial intelligence
We use AI models to generate advertising content (ad copy, job descriptions, hooks) based on information provided by our Clients about their offers and services. These processing operations concern offer and brief data, not the personal data of prospects.
No automated decision producing legal or significant effects on prospects is made on the basis of these processing operations, in accordance with Article 22 of the GDPR.
9. Cookies
Our Services use only cookies strictly necessary for technical operation (authentication, security). These cookies do not require your consent under Article 82 of the French Data Protection Act.
We do not use advertising, tracking, or behavioral analytics cookies on our own domains. Third-party advertising platforms (Meta, TikTok, LinkedIn, etc.) use their own tracking technologies, governed by their respective privacy policies.
10. Your rights
In accordance with the GDPR and the French Data Protection Act, you have the following rights:
- Right of access: obtain confirmation that your data is being processed and receive a copy.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure: request the deletion of your data, subject to our legal obligations.
- Right to restriction: request the temporary suspension of processing.
- Right to object: object to processing based on legitimate interest, including commercial prospecting.
- Right to portability: receive your data in a structured, machine-readable format.
- Right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
How to exercise your rights
Send your request by email to: gael@getcaptive.ai
We will respond within one month from receipt of your request. This period may be extended by two months in case of complexity or high volume of requests, in which case you will be informed.
If your request concerns data that has been transmitted to one of our Clients, we will also direct you to the Client concerned, which becomes the data controller for the data in its possession.
Right to object to commercial prospecting
You may at any time object to receiving commercial communications (SMS, email) by using the unsubscribe link in each message, by replying "STOP" to an SMS, or by contacting us at the address above.
Complaint to the supervisory authority
In the event of persistent disagreement, you may lodge a complaint with the French Data Protection Authority (CNIL): www.cnil.fr.
11. Minors
Our Services are not intended for individuals under 16 years of age. We do not knowingly collect data from minors. If we discover that data from a minor has been collected without parental consent, we will delete it as soon as possible.
12. Updates to this policy
We reserve the right to modify this policy at any time. In the event of a material change, we will notify users of our Services through a platform notification or by email. The last update date is indicated at the top of the document.
13. Contact
For any question regarding this policy or the protection of your data:
Captive SAS
6 rue d'Armaillé, 75017 Paris, France
Email: gael@getcaptive.ai