Privacy policy
Last updated: sptember 10, 2026
ARTICLE 1: Definitions
The “Site” refers to the promotional ComInTime website developed and designed by the development agency WEB&DESIGN using computer formats suitable for use on the Internet. The Site contains various types of data, including texts, sounds, still or animated images and videos intended to be publicly accessible at https://www.comintime.com.
The “Software Solution” refers to the ComInTime web and mobile applications developed and designed by the development agency WEB&DESIGN. The Software Solution contains various types of data (texts, sounds, still or animated images, videos), intended to be accessed privately at https://app.comintime.com or through the ComInTime mobile application available for download from Google Play or Apple’s App Store.
The term “Mobile Application” refers to application software distributed within the environment of multifunction mobile phones (or smartphones) and tablets, i.e. individual portable devices providing access to the Internet and, in most cases, telephone networks, and which may allow third-party applications to be installed and run.
The terms “personal data”, “processing”, “data subject”, “data controller”, “processor” and “recipient” have the meanings given to them by Regulation (EU) 2016/679 of April 27, 2016 (GDPR) and the amended French Data Protection Act No. 78-17 of January 6, 1978.
ARTICLE 2: Scope
This personal data protection policy (hereinafter the “Policy”) is intended to inform Data Subjects about how their personal data is collected and processed by WEB&DESIGN as part of the ComInTime online service (website and Software Solution).
This Privacy Policy applies to all personal data processing carried out in connection with the use of the ComInTime website and the ComInTime web and mobile applications published by WEB&DESIGN SARL, with a share capital of €7,840.00, registered with the Belfort Trade and Companies Register under number B 502 588 882, whose registered office is located at 4 avenue Carnot, 25200 Montbéliard, France, as well as to data collected through cookies or equivalent technologies.
ARTICLE 3: Identity of the Data Controller and DPO Contact Details
The Data Controller is:
WEB&DESIGN SARL, with a share capital of €7,840.00, registered with the Belfort Trade and Companies Register under number B 502 588 882, whose registered office is located at 4 avenue Carnot, 25200 Montbéliard, France.
WEB&DESIGN’s Data Protection Officer (DPO) is Mr Guillaume DOBBELS and may be contacted at the following address: https://www.comintime.com/en/contact .
ARTICLE 4: Processing of Personal Data
WEB&DESIGN is committed to protecting the privacy of its users in accordance with applicable regulations, in particular the French Data Protection Act (“Informatique et Libertés”) and the GDPR. As part of the ComInTime online service (website and Software Solution), WEB&DESIGN collects the following personal data:
- First name
- Last name
- Email address
- Telephone number
- Company
- Job title
- Company address
- Connection data (IP address, logs, etc.)
This data is used exclusively to create personalised and secure access to the Software Solution and to contact users in order to improve our services, provide support services and offer communication-related advice.
In addition, WEB&DESIGN may process personal data through its Software Solution when it is interconnected with social networks configured by the user (Facebook, LinkedIn, etc.), as well as any other data voluntarily provided when using the services, without necessarily collecting or storing such data.
Request for deletion of personal data
Any user wishing to request the deletion of personal data associated with their ComInTime account may do so by sending an email to equipe@webetdesign.com.
The request must be sent from the email address used when the account was created on the platform and must have the following subject line: “ComInTime account deletion request”.
Upon receipt of this request, WEB&DESIGN will delete the personal data associated with the account as soon as reasonably possible, subject to any legal retention obligations that may apply. Confirmation that the request has been processed may be sent to the user by email.
ARTICLE 5: Data from Google Services
Nature of the connection
ComInTime allows the User to connect their Google account in order to access the Google Business Profile locations they are authorised to manage and to publish updates from ComInTime to the selected business profiles.
This connection uses Google’s OAuth 2.0 protocol. WEB&DESIGN never collects or has access to the password of the User’s Google account.
Data accessed and processed
As part of this connection, ComInTime may access the following data:
- identifier of the connected Google account;
- associated email address, where this permission is requested;
- list of accessible Google Business Profile accounts and locations;
- identifiers, names, addresses and information required to identify the locations;
- management permissions associated with the connected account;
- status and results of publications made;
- OAuth access and refresh tokens required to maintain the connection.
Only data strictly necessary for the operation of the features requested by the User is accessed and processed.
Purposes of processing
This data is used exclusively to:
- allow the User to connect their Google account;
- display the locations they are authorised to manage;
- allow them to select the relevant business profiles;
- send Google the content they have approved or scheduled;
- execute scheduled publications;
- display publication results or any publication errors;
- ensure the security and technical maintenance of the connection.
Data obtained from Google is not used for advertising, commercial profiling or resale purposes. It is not used to train, develop or improve general-purpose or non-personalised artificial intelligence models.
Retention and security
ComInTime stores only the technical identifiers and authorisation tokens required for the connection to operate and for scheduled publications to be executed.
This data is retained for as long as the Google connection remains enabled by the User. It is protected using appropriate technical and organisational measures designed to prevent unauthorised access, alteration or disclosure.
Data transmission
Content approved or scheduled by the User is transmitted to Google so that it can be published on the selected Google Business Profile listings.
Data obtained through Google services is not sold, rented or disclosed to third parties for advertising purposes. It may only be accessible to technical service providers that are essential to the operation of ComInTime, within the limits of their assigned responsibilities, or disclosed where required by law.
Revocation and deletion
The User may revoke ComInTime’s access to their Google account at any time:
- from the connection settings within ComInTime;
- from the security settings of their Google account;
- by submitting a request through our contact form.
Content previously published on Google Business Profile is not automatically deleted when the account is disconnected. Such content may be managed directly from Google Business Profile, subject to the features provided by Google.
Deleting the ComInTime account results in the deletion of associated Google data in accordance with the conditions and timeframes specified in this Policy.
ARTICLE 6: DATA FROM META SERVICES (FACEBOOK AND INSTAGRAM)
Nature of the connection
ComInTime allows its users to connect their account with Meta services, including Facebook and Instagram.
This connection allows the user, in particular, to select the Facebook Pages and Instagram accounts they manage, manage and publish content to these accounts, and view their statistics directly from the ComInTime application.
Access to Meta services is provided through the APIs and authorisation mechanisms made available by Meta and within the limits of the permissions granted by the user.
Data accessed and processed
As part of this connection, ComInTime may access and process data provided through the Meta APIs that is necessary for the features being used, including:
- information used to identify the connected Facebook Pages and Instagram accounts;
- the name and public information of the relevant accounts and Pages;
- profile images of the accounts and Pages;
- posts and associated content;
- statistics relating to posts, including reach, interaction and engagement data;
- information required to manage the permissions granted to ComInTime;
- access tokens issued by Meta.
ComInTime only accesses this data to the extent necessary for the operation of the features requested by the user.
Purposes of processing
Data obtained through Meta services is used exclusively to provide the features offered by ComInTime, including:
- identifying and displaying connected Facebook Pages and Instagram accounts;
- enabling content to be published and managed from ComInTime;
- displaying connected accounts and Pages together with their profile images;
- retrieving, storing and displaying statistics relating to posts;
- maintaining the connection between ComInTime and Meta services.
Data obtained through the Meta APIs is not used for purposes unrelated to the features requested by the user.
Storage and retention period
In order to ensure the operation of the connection, ComInTime stores the access tokens provided by Meta in its database.
Profile images of connected accounts and Pages may also be stored locally so that they can be displayed within the ComInTime interface.
Statistics relating to the various posts are stored so that they can be viewed and monitored from within the application.
This data is retained for the entire duration of the ComInTime account or for as long as it remains necessary for the operation of the Facebook and Instagram features used by the user.
It is deleted when it is no longer necessary for the operation of the service, when the relevant account is deleted, or following a deletion request submitted by the user.
Revocation of access and deletion of data
The user may request the revocation of the connection between ComInTime and Facebook and Instagram services at any time.
The user may also request the deletion of data obtained through Meta services and stored by ComInTime, including access tokens, locally stored profile images and statistics associated with posts.
Requests for revocation or deletion may be submitted by email to equipe@webetdesign.com.
Once the request has been processed, ComInTime will revoke the relevant connection and delete the associated Meta data stored in its systems.
Use of Meta data
ComInTime uses data obtained through the Meta APIs solely for the features requested by the user and in accordance with the permissions granted by the user.
This data is neither sold nor used by ComInTime for advertising purposes or for purposes unrelated to the Facebook and Instagram features offered within the application.
ARTICLE 7: Purposes and Legal Bases for Processing
Data is processed for the following purposes:
- User account creation and management (performance of a contract)
- Secure access to the platform (performance of a contract)
- Customer assistance and support (legitimate interest)
- Commercial prospecting (consent or legitimate interest)
- Improvement of services (legitimate interest)
- Compliance with legal and regulatory obligations (legal obligation)
ARTICLE 8: Rights of Data Subjects
WEB&DESIGN undertakes to ensure that collected data is retained in a form allowing Data Subjects to be identified for no longer than one year without activity by the Data Subject and, in any event, only for as long as necessary for the purposes for which the data is collected and processed.
In accordance with the French Data Protection Act of January 6, 1978, as amended by the Act of August 6, 2004, and with the provisions of the GDPR, you have the right to access, modify, rectify and delete personal data concerning you where such data is inaccurate, incomplete, ambiguous or outdated. You also have the right to object, on legitimate grounds, to the processing of personal data concerning you.
You may exercise these rights by sending a postal letter together with proof of identity to the following address: WEB&DESIGN, 4 avenue Carnot, 25200 Montbéliard, France.
We will retain a copy of your identity document only for the period required to process your request.
You also have the right to lodge a complaint with the CNIL, the French data protection authority.
ARTICLE 9: Data Recipients
Data may only be accessed by:
- authorised personnel within WEB&DESIGN;
- authorised personnel of our partners and processors, as well as any person involved in the performance of the contract with you, including the hosting provider for the Site and the Software Solution: KOULA (RCS Nanterre B 417 680 618 – FR37417680618), whose registered office is located at 175-177 rue d'Aguesseau, Boulogne-Billancourt (92100), France;
- organisations, officers of the court, public officials, judicial authorities and administrative authorities, under the conditions provided for by law.
The use of your personal data by third parties outside our company is governed by their own privacy policies.
ARTICLE 10: Transfer of Personal Data
WEB&DESIGN reserves the right to transmit the personal data of Data Subjects solely in order to comply with its legal obligations, particularly where it is required to do so pursuant to a judicial request or order.
ARTICLE 11: Transfers Outside the European Union
Data is hosted in France and is processed primarily within the European Union.
If a transfer outside the European Union is envisaged, to which you consent, we ensure that such transfers are made to countries providing an adequate level of protection or are governed by legal mechanisms ensuring a level of protection compliant with European requirements. The Company undertakes to implement the appropriate safeguards provided for by the GDPR, such as Standard Contractual Clauses, adequacy decisions or other applicable safeguards.
ARTICLE 12: Security
The Company implements all appropriate technical and organisational measures to ensure the security and confidentiality of personal data, including encryption, access management, backups and regular audits.
ARTICLE 13: Cookie Policy
When visiting the Site, the placement of cookies on the device you use (the “Device”) is subject to your consent whenever those cookies are not strictly necessary for the operation of the Site.
Cookies used on the Site may collect data relating to a Device or to behaviour at a given time, including:
- the IP address of the connected Device;
- the date, time and duration of a visit to a page or the entire Site;
- the number of pages viewed;
- the browsing path;
- the type of operating system;
- the type and version of browser software used;
- the brand and model of the mobile device or tablet;
- the language used.
First-party cookies are generated and stored locally by the Software Solution to ensure the proper operation of the web and mobile applications, whereas third-party cookies are generated by our providers or social networks to help us better understand our audience.
These cookies enable us to measure the performance of our marketing activities in order to provide you with increasingly relevant content tailored to your expectations. These include:
- Bing Ads
- Google Ads
- Microsoft Ads
- Google Analytics
The first time you visit the Site, a cookie banner is displayed offering you the option to accept all cookies, reject all cookies, or make a customised selection on a cookie-by-cookie basis.
You may change your choices at any time and configure them again by accessing the cookie management interface located at the bottom left of our website.
The technical cookie storing your choice is placed on your Device for a period of six months. At the end of this period, we will ask you again to accept, configure or reject cookies. You may reject them at any time through our cookie banner.
If you accept cookies, the information recorded through them will be retained for a maximum period of 13 months.
ARTICLE 14: Updates to the Privacy Policy
This Privacy Policy may be amended at any time.
We encourage you to review this Privacy Policy regularly to stay informed of any changes. Any material changes will be notified to users by email or through the application. The date of the latest update appears at the beginning of this document.
This Privacy Policy is binding upon you as soon as you visit our Site or download our application.