Easyexpat International Logo

Privacy Policy

Updated on 03.09.2025

This policy is established in accordance with the Swiss Federal Data Protection Act (nLPD, RS 235.1) which came into force on September 1, 2023, as well as Regulation (EU) 2016/679 (GDPR).

This Privacy Policy describes how Easy Expat International SA ("EEI", "we") collects and processes your personal data when you use our platform. Data processing is carried out in accordance with applicable data protection legislation in Switzerland and the European Union (GDPR), according to the operations and locations concerned.

1. Data Controller

Easy Expat International SA is responsible for the processing of personal data processed via the Service. The subsidiaries "EASY EXPAT FRANCE" and "EASYEXPAT UK" may act as co-controllers or processors for operations located in their territories. For any questions, contact us via the contact details indicated on the site or your HR contact.

2. Hosting and Storage

The application and its databases are hosted in Switzerland with Infomaniak Network SA (Rue Eugène‑Marziano 25, 1227 Les Acacias – Geneva, Switzerland). Sensitive files (e.g. payslips, expense reports, invoices, contractual documents) are stored exclusively on servers located in Switzerland. Transactional emailing is provided by Postmark (postmarkapp.com). Some technical subcontractors may process metadata (e.g. telemetry, emailing) in or outside Switzerland/EEA, in accordance with the "International Transfers" section.

3. Data Collected

  • Identification: surname, first name, email, telephone numbers.
  • Professional Profile: CV (FR/EN), positions, skills, availability, languages, HR documents.
  • Contractual Relations: contract information, general/specific terms, validations (timesheets, expense reports).
  • References: referees' emails, opinions provided via secure link.
  • Usage Data: technical logs, preferences (language), interactions with modules (statuses, timestamps).

4. Purposes

  • Management of user accounts (candidates/employees/clients) and profiles.
  • Publication and management of job offers; processing of applications.
  • Collection of reference opinions via secure link, tracking of responses.
  • Time management (timesheets): input, consolidation, validation circuits (client/administration), documents and signatures.
  • Management of expense reports: input, supporting documents, validation/refusal and tracking.
  • Contract management: terms, notifications, associated documents.
  • Continuous improvement, security and maintenance of the platform.
  • Compliance with legal, social, accounting and compliance obligations.

5. Legal Bases

Detailed Legal Bases by Processing:

  • User Account Management: performance of the service contract or pre-contractual measures (art. 6.1.b GDPR, art. 31 para. 2 let. a nLPD).
  • Recruitment and Job Posting: legitimate interest in identifying the best candidates and filling positions (art. 6.1.f GDPR, art. 31 para. 1 nLPD).
  • Collection of Professional References: legitimate interest of EEI and its clients in evaluating candidate suitability (art. 6.1.f GDPR, art. 31 para. 1 nLPD).
  • Contractual and Administrative Management: performance of employment and service contracts, legal accounting and social obligations (art. 6.1.b and 6.1.c GDPR, art. 31 para. 2 let. a and c nLPD).
  • Security and Technical Maintenance: legitimate interest in ensuring security, service continuity and incident detection (art. 6.1.f GDPR, art. 31 para. 1 nLPD).
  • Marketing communications: explicit consent, revocable at any time.

6. Sharing, Processors and Recipients

Access is limited to authorized persons at EEI and, if necessary, to service providers (hosting, support, HR tools) subject to confidentiality and security obligations. In case of assignment, strictly necessary data may be shared with involved clients and partners. All processors are subject to contractual clauses ensuring a level of security and confidentiality compliant with nLPD and GDPR. The updated list of our processors can be provided on request.

7. Cookies and Similar Technologies

We primarily use cookies strictly necessary for the operation and security of the Service (e.g. session maintenance, protection against fraudulent use). When non-essential analytical or functional cookies are deployed, they are only deployed after obtaining your consent, which you can withdraw at any time via the settings provided or your browser. You can also configure your browser to refuse certain cookies; however, this may limit certain functionalities.

8. International Transfers

Given our international presence, transfers outside Switzerland/EEA may take place. We apply adequate safeguards (e.g. European Commission standard contractual clauses, equivalent Swiss safeguards) and, if necessary, additional measures, to ensure a substantially equivalent level of protection.

9. Retention Periods

Specific Retention Periods:

  • Candidate Data: retained as long as necessary for our recruitment activities and legal obligations. Deletion only upon your express request or when legally required.
  • Current and Former Employee Data: retained indefinitely for our HR files, future reference management and our accounting/social obligations (10 years minimum). Deletion only upon express request.
  • Reference and Evaluation Data: retained indefinitely as essential for our HR consulting activities and evaluation history. Deletion only upon referrer's request.
  • Validation Data: timesheets and expense reports retained according to accounting obligations (10 years minimum).
  • Technical Logs and Metadata: retained for a maximum of 2 years to ensure security, traceability, and service improvement.
  • Access and Security Logs: retained as long as necessary for the security of our systems and continuity of our activities.
  • Telemetry and Usage Data: retained indefinitely for continuous improvement of our services and analysis of our activities.
  • Backups and Archives: retained indefinitely to ensure continuity of our activities and serve as evidence in case of litigation.

10. Security

We implement reasonable technical and organizational measures (access controls, encryption in transit, logging, backups, internal procedures).

We have implemented appropriate and reasonable technical and organizational security measures to protect the security of personal information we process. However, despite our protective measures and efforts to secure your information, no electronic transmission over the internet or information storage technology can be guaranteed 100%, so we cannot promise or guarantee that hackers, cybercriminals or other unauthorized third parties will not be able to defeat our security and inappropriately collect, access, steal or modify your information. While we do our best to protect your personal information, the transmission of personal information to and from our services is at your own risk. You should only access the services in a secure environment.

10-bis. Personal Data Breaches

In the event of a personal data breach likely to present a high risk to your rights and freedoms, we will inform you as soon as possible in accordance with applicable regulations. We will document any security incident and take appropriate corrective measures.

11. Your Rights

Under applicable law (nLPD/GDPR), you have the following rights in particular:

  • Right of Access: obtain confirmation that data concerning you is being processed and receive a copy of it.
  • Right of Rectification: have inaccurate or incomplete data corrected.
  • Right to Erasure ("Right to be Forgotten"): obtain the deletion of your data, within the limits provided by law.
  • Right to Restriction of Processing: temporarily restrict certain processing.
  • Right to Object: object to certain processing based on legitimate interest.
  • Right to Data Portability: receive your data in a structured format and/or request their transmission to a third party, where applicable.
  • Right to Withdraw Your Consent: at any time for processing based on consent, without affecting prior lawfulness.
  • Right to Lodge a Complaint: with the competent supervisory authority.

12. Exercising Your Rights

To exercise your rights (access, rectification, erasure, etc.), contact us via the contact details indicated on the site or your HR contact. Any request for account deletion and all associated data must be addressed in writing to the address contact@easyexpat-international.com. We may verify your identity before processing the request and will retain data required by law for mandatory periods.

13. Complaints

You can address a complaint to the competent authority (in Switzerland: Federal Data Protection and Information Commissioner; in France: CNIL), without prejudice to any other recourse.

14. Modifications

We may modify this Policy at any time. The version in force is the one displayed on this page on the date indicated in the header. When required, we will inform you of significant changes through an appropriate channel.