- Job title
- Graphic Designer
- Sector
- Packaging
- Organization type
- 40-person manufacturing company
- Joined
- Feb 2025
- Message
- 137
We provide corporate event and catering services based in Lyon. We have a core team of 4 and an annual revenue of around 260,000 EUR. Our clientele includes local French businesses as well as organizations with ties to Turkey. Over time, through quote forms, email exchanges, and WhatsApp, we've gathered names, phone numbers, company names, and even dietary or allergy requirements from hundreds of corporate reps and attendees.
Last week, an international corporate client asked for our privacy notice, a summary of our data processing inventory, and a transparency compliance report before signing. That's when we realized we have nothing official on our site besides a generic two-paragraph privacy policy copied and pasted off the web in a rush.
Given RGPD in France and our touchpoints with Turkey under KVKK, how should we build this process from the ground up to be fully compliant? What sections are mandatory in a privacy notice, at what touchpoints must we present them to clients, and how do we determine data retention periods?