Legal
Privacy policy (GDPR)
Sourcing.sh maintains an index of professional data (companies, offers, signals and people) serving AI agents and recruitment and go-to-market teams. This policy describes how we treat personal data, whether you are a user of the service or an individual listed in the index.
Last update: September 7, 2026
01Data controller
The data controller is TACL GROUP, publisher of Sourcing.sh, a simplified single-member joint stock company (SASU) with capital of €1.00, registered with the Paris RCS under number 982 948 978, whose head office is located at 58 rue de Monceau, CS 48756, 75008 Paris, France, represented by its president, Titouan Albouy.
Privacy contact: privacy@sourcing.sh. This address is the point of contact for questions relating to personal data and the exercise of rights.
02Scope: who is affected
This policy covers two distinct situations:
- Registered users : you have created an account or requested access. We process your data within the framework of the contract between us (sections 3 and 4).
- People listed in the index without having an account : your publicly accessible professional data has been aggregated in our index. You have no contractual relationship with us; section 5 is dedicated to you, as well as the page /your-data to exercise your rights.
Simple visitors to the site are also affected by the sections relating to cookies and audience measurement.
To create its own index, TACL GROUP determines the purposes and means of processing. For CRM or ATS data entrusted solely to carry out a client's instructions, responsibilities and instructions must be set out in a subcontracting agreement before they are taken over. Connecting a tool does not constitute authorization to reuse its data to enrich the Index.
03Data processed
- Registered users : identity, professional email, company and function, connection identifiers, API and MCP server usage logs, billing data.
- People indexed : strictly professional data: name, position, current employer and background, publicly declared skills, public professional contact details, public profile URLs. The service does not aim to collect sensitive data (art. 9 GDPR), information on private life or data of minors. Any undue presence may be reported for review and removal.
- Visitors : navigation data (see “Cookies” section).
The public site only displays anonymous aggregates: the nominative data in the index is only accessible to authenticated users, under contract and within the limits of the T&Cs.
04Purposes, legal bases and retention periods
Each processing is based on one of the bases provided for in Article 6 of the GDPR, summarized below:
| Purpose | Data | Legal basis | Preservation |
|---|---|---|---|
| Respond to access, demonstration and report requests | Name, email, company, optional telephone, availability, message and simulation volumes | Pre-contractual measures at your request (art. 6.1.b); legitimate interest for B2B exchanges (art. 6.1.f) | Duration necessary to follow up on the request; at most 3 years after the last active contact for prospects, unless opposed or legally required |
| Provision of service to registered users (account, access to the index, billing) | Identity, professional email, company, connection logs, billing data | Execution of the contract (art. 6.1.b) | Duration of the relationship; deletion or anonymization of operational data within 30 days following closure, excluding legally necessary retention |
| Creation and updating of the professional data index (people indexed) | Professional identity, position, employer, career path, public professional contact details | Legitimate interest (art. 6.1.f), see section 5 | Conservation conditioned on a current purpose and the relevance of the data; re-examination at each check, withdrawal of data that has become useless or is the subject of an applicable opposition |
| Prospecting and commercial communication (newsletters, product announcements) | Email, communication preferences | Consent (art. 6.1.a), withdrawable at any time | Until consent is withdrawn, at most 3 years after the last contact |
| Operation and security of the site | Session items, display preferences, and technical connection information | Legitimate interest in ensuring operation and security (art. 6.1.f) | Session and duration necessary for security; theme preference until changed or cleared in the browser |
| Legal obligations (accounting, requisitions) | Invoices, contractual data | Legal obligation (art. 6.1.c) | 5 years (commercial prescription) to 10 years (accounting documents) |
| Processing GDPR requests (page /your-data) | Name, email, profile URL, request content | Legal obligation (art. 6.1.c, art. 12 to 21 GDPR) | Active file until closed; minimum supporting documentation archived for up to 5 years if necessary for proof, without systematic retention of identity documents |
05Persons appearing in the index (information art. 14 GDPR)
In accordance with Article 14 of the GDPR, which applies when data is not collected directly from the data subject, here is the information due to the people appearing in our index:
- Data sources : public professional profiles (LinkedIn and equivalent networks), job sites and career platforms, websites and company team pages, professional portfolios and personal sites, public registers and providers of professional and enrichment data. The available source of a recording, including the relevant provider, may be requested as part of the right of access. This list describes the categories of sources; it does not mean that every site is queried for every person.
- Legal basis: legitimate interest (art. 6.1.f) : provide recruitment and go-to-market professionals with a reliable index of data already made public in a professional context.
- Limits of reuse : the public nature of data is not enough to authorize its collection or marketing. The use of legitimate interest presupposes a specific purpose, necessary processing and an examination of the rights, reasonable expectations and objections of individuals. Source restrictions and third party rights must also be respected. You can request clarification on the processing of your data at privacy@sourcing.sh.
- Information of people : this section, the page /your-data specify your rights. Where Article 14 applies, individual information must be provided within a reasonable time, at the latest within one month of obtaining the data, or earlier upon first communication or transmission to a recipient. The mere publication of this page does not replace this obligation. Any exception must meet the conditions of the GDPR and be documented.
Are you included in the index and would like to view, correct or delete your data?
A dedicated form allows you to submit a request without creating an account. A response is provided within the time limit set by the GDPR, in principle one month.
06Recipients and subcontractors
Sourcing.sh markets access to professional data and research, updating and enrichment services. Personal data may therefore be communicated to professional clients for remuneration. They are not published with open access on the site. The recipients are:
- Technical subcontractors : Lovable for publishing the site, Cloudflare for its distribution and security, and Supabase for the database and authentication. Sending the simulation report by email uses Resend when enabled; local download of the report does not require this sending. The site does not collect credit card numbers. Service providers must only receive the data necessary for their mission.
- Service clients, including via AI agents and MCP server : authenticated users (humans or AI agents acting on their behalf) access the index data within the framework of the T&Cs, which notably prohibit them from any model retraining on the corpus and any republication. They become responsible for their own downstream processing.
- Authorities : upon legal request only.
07Transfers outside the European Union
Some technical service providers are established outside the European Union, particularly in the United States. The location of a provider alone does not determine the location of all data or support access. Any transfer subject to Chapter V of the GDPR must be governed by an applicable mechanism: adequacy decision or appropriate guarantees, in particular standard contractual clauses, with the necessary additional assessments and measures. You can request information on destinations and a copy of the guarantees applicable to your treatment at privacy@sourcing.sh.
08Your rights
In accordance with articles 15 to 21 of the GDPR, you have the rights of access, rectification, erasure, limitation, portability and opposition, under the conditions provided for each of these rights, as well as the right to withdraw your consent at any time for the processing which depends on it.
To exercise them: the form /your-data (recommended for index people) or privacy@sourcing.sh. We respond without undue delay, in principle within one month. This deadline may be extended by two months due to the complexity or number of requests; you will be informed with the reasons within the first month. In the event of reasonable doubt about identity, only the information necessary for its verification is requested. Opposition to commercial prospecting does not have to be justified. For other processing based on legitimate interest, your particular situation is examined. Retention that is legally necessary or intended to prevent reinstatement after opposition is limited to the data and duration necessary.
If you believe that your rights are not respected, you can contact the CNIL (National Commission for Information Technology and Liberties), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, cnil.fr/fr/complaints.
09Cookies and audience measurement
The site uses session and security mechanisms and remembers your choice of light or dark theme in the browser's local storage. Cloudflare may set a cookie to protect against bots. The connected space stores the elements necessary for authentication; Disconnecting ends the session on the browser side. These technical uses are not used for targeted advertising.
No advertising tool is integrated into the site code. Visitor statistics may be provided by the publishing platform. Non-strictly necessary trackers that do not benefit from an exemption must remain deactivated as long as a consent mechanism also allowing refusal and withdrawal of choice is not available. You can clear local data from your browser; this may log you out and reset your preferences.
10Security
The protection of the service is based in particular on HTTPS, authentication, administrative rights and basic access restrictions. Access to requests received by the site is reserved for authorized persons. Security measures must be adapted to the data processed and do not constitute a guarantee of the absence of incidents. To report a vulnerability or incident, write to contact@sourcing.sh, without attaching a password, API key or massive copy of personal data.
11Updates to this policy
This policy may evolve with the service. Any substantial modification is reported on this page (update date at the top) and, for registered users, by email. Current version: September 7, 2026.