Privacy Policy
This Privacy Policy applies to anyone who browses the DSTI institutional website or a platform to which it refers, uses services for admissions or the administrative and pedagogical management of students, or otherwise interacts with Data ScienceTech Institute through those services (a “user”).
Data ScienceTech Institute (DSTI School of Engineering, “DSTI”) is the data controller for the processing described in this notice. DSTI protects personal data in accordance with Law No. 78-17 of 6 January 1978 as amended (the French Data Protection Act), Regulation (EU) 2016/679 (the “GDPR”) and other applicable requirements.
The services have separate scopes. The DSTI Application System processes prospective-applicant and applicant information. DSTI Learn is DSTI’s student-records and pedagogical-management platform after enrolment. The optional ChatGPT connector is an alternative interface to limited Application System functions; it is not the canonical application or student record.
Last modified and effective: 24 July 2026.
1. The data collected by Data ScienceTech Institute
In the context of the institutional portal, research laboratory sites and organised events,
Data ScienceTech Institute may be required to collect and process the following user data: Name, First name, Telephone, Email, Student number, Position, Company.
In the context of the admissions platform,
Data ScienceTech Institute may be required to collect and process the following user data:
Identity and contact details:
title, name, first names, address, telephone number (landline and/or mobile), fax number, email addresses, date of birth and place of birth, nationality, photo, photocopy of a national identity card;
Family, economic and financial situation:
marital life, socio-professional category and profession of parents, type of scholarship, national service;
Professional life:
CV, cover letter, copy of transcripts and diplomas obtained, letter of recommendation;
NIT authentication elements;
Personal data of an academic or professional referee of the candidate:
name, first name, title, email address, establishment.
In the context of the housing platform,
Data ScienceTech Institute may be required to collect and process the following user data:
Identity:
title, name, first names, telephone number, email, country of origin, photocopy of a national identity card;
Family, economic and financial situation:
employer establishment, training followed, type of contract, place of work.
The mandatory nature of the information that the user must provide on the site is indicated at the time of data collection and on the corresponding forms by an asterisk and/or a list of mandatory fields. Any failure to respond or any response deemed abnormal by Data ScienceTech Institute may result in the refusal of the establishment to take into account the user’s request.
In the context of its higher education and professional training activities,
Data ScienceTech Institute may be required to collect and process the following user data:
Identity and contact details:
title, name, first names, address, telephone number, email, date and place of birth, nationality, family situation, photo;
Professional life:
employer, profession, salary, CV, cover letter, copy of transcripts and diplomas obtained, letter of recommendation.
Data ScienceTech Institute maintains close links with DSTI Alumni, the community of graduates and students of DSTI and the Data ScienceTech Foundation. As such, Data ScienceTech Institute is likely to propose to the user to provide certain personal data for prospecting/marketing communication purposes (sending newsletters, invitations to events, etc.).
The user can explicitly and freely consent or not to the collection and processing of his personal data for these purposes by means of a checkbox. The user also has the possibility, at any time, to unsubscribe, at least by email, or through a dedicated interface.
In the context of events organised in person or online,
Data ScienceTech Institute may take photographs of participants or record online events for non-commercial use. If you do not wish the school to use your image, you retain a right to erasure by contacting us at the following address: contact@dsti.institute
In the context of DSTI Learn,
DSTI Learn processes enrolment and academic standing; programme, intake and learning-activity information; academic lifecycle movements such as enrolment, progression, study pause, withdrawal, transfer, disciplinary suspension or exclusion; and the staff member and reason recorded for a movement.
It also processes academic committee membership, minutes, decisions, deliberations and annexes; Pastoral records concerning meetings, support, warnings and follow-up; finance, payment-plan, invoice, receipt and refund records; timetabling and external-teacher information; Examination integrity reviews; professional certifications; academic distinctions; issued transcripts and attestations with verification and revocation records; and related calendar links.
Special-category data in DSTI Learn
DSTI Learn is designed to minimise Article 9 special-category data. A committee’s structured outcome does not state a health ground. A health reference may appear only in a restricted free-text deliberation and is processed under Article 9(2)(f) GDPR where necessary for the establishment, exercise or defence of legal claims. Pastoral health markers and examination arrangements may also reveal health or disability information and are access-restricted. A health-related pastoral record is always erased following a valid erasure request.
In the context of the Application System and optional ChatGPT connector,
The Application System processes the identity, contact, application, academic-background, programme, route, intake, eligibility, requirement, status, document-provision and approved study-abroad Agent relationship information needed to administer an application. Its identity service processes the verified email address and access role needed to authenticate and authorise access.
The optional connector exposes only data needed for the authenticated action. It may show a data-minimised application summary, country-level facts required by a DSTI rule, requirement findings and opaque application, request or confirmation references. It does not expose exact address, telephone number, date or city of birth; guardian details; passwords or one-time codes; identity documents, applicant documents or document contents; payment-card or bank details; tuition amounts; unrestricted provider records; or diagnostic logs.
The connector is not designed to request or return Article 9 special-category data. Applicants should not put special-category data into ChatGPT. Supporting documents and unrestricted free text remain on the secure DSTI Web application, where an applicant may voluntarily provide information that DSTI must then handle under the appropriate access, legal-basis, retention and rights controls.
2. The purposes of processing
As a data controller, Data ScienceTech Institute collects the personal data of users in a lawful and fair manner and respecting their rights. The main objective of collecting personal data is to offer users a safe, optimal, efficient and personalised experience.
In the context of the institutional portal,
the information collected by Data ScienceTech Institute, including personal data, can be used for the following purposes (according to the consent wishes expressed by the user):
- Manage the creation of the user account;
- Manage the submission of application files for Data ScienceTech Institute training courses;
- Collect the recommendations of the academic or professional referees of candidates for Data ScienceTech Institute training courses;
- Send newsletters and other prospecting messages and participation in cultural events (with the consent of the user);
- Develop statistics and improve the site and services; Communicate with users and answer their questions;
- Make known the developments in the School’s educational offer;
- Inform about the partnership initiatives developed by the School;
- Search for speakers for the courses; Comply with applicable legislation and regulations.
In the context of the DSTI website,
the information collected by including personal data, can be used for the following purposes (according to the consent wishes expressed by the user):
- Process your request for registration for an event,
- downloading a document,
- request for information or application;
- Contact you about our services and continuing education programmes;
- Contact you about the free events we organise for professionals.
DSTI Learn purposes
- Administer enrolment, progression and graduation;
- Convene and record academic committees and implement their decisions;
- Provide and record pastoral care and student follow-up;
- Bill tuition and record payments;
- Schedule teaching and uphold examination integrity;
- Issue transcripts and attestations and permit authenticity verification; and
- Meet legal, accreditation, academic and accounting obligations.
Application System and connector purposes and legal bases
DSTI uses Application System and connector information to authenticate and authorise an applicant or approved Agent; perform the application action requested; apply DSTI’s backend rules; prevent cross-applicant and cross-agency access; preview and apply only an explicitly confirmed change; maintain security, auditability, reliability and safe retries; and direct protected activity to the secure Web application.
- Article 6(1)(b) GDPR: application and admissions steps taken at the applicant’s request before entering into a contract;
- Article 6(1)(f) GDPR: DSTI’s legitimate interests in authentication, access control, fraud prevention, auditability, operational reliability and safe retries;
- Article 6(1)(c) GDPR: processing required to comply with a legal obligation; and
- Article 6(1)(a) GDPR: separately optional processing that genuinely relies on consent, such as marketing. Choosing the optional connector is not itself the legal basis for processing an application.
3. Data collected through cookies
Cookies may be used on the site. Cookies are small files that are stored on the user’s computer or on any electronic communications device used by the user when browsing the site. These files allow the exchange of status information between the site and the user’s browser.
Data ScienceTech Institute thus uses the following cookies:
Navigation cookies:
These cookies are essential for the proper functioning of the site and its features. These cookies do not collect information intended to be used for commercial prospecting or advertising targeting.
Performance cookies:
These cookies collect information about the ways in which the site is used by all users. Performance cookies help in particular to identify particularly popular sections of the site and to count the number of visits. These elements allow the content of the site to be adapted according to the needs of users and thereby improve the offer and ergonomics of the services offered on the site. To exploit the data for statistical purposes, the Site uses the Google Analytics tool.
However, we draw your attention to the fact that by setting the browser to refuse the cookies deposited by Data ScienceTech Institute, some features or pages of the site may be difficult to access or even inaccessible.
The prior consent of the user, via the cookie banner displayed on the site, is required before any reading or any deposit of cookies that are not strictly necessary for the operation of the Site and/or the provision of services.
Non-necessary cookies for the operation of the site and/or services are deposited for a maximum period of 13 months. Beyond this period, the user’s consent will be required again before the deposit of any new cookie.
You can accept or refuse cookies by modifying the settings of your browser.
You can delete all cookies that have been installed in the cookie folder of your browser.
Each browser offers different procedures to manage your settings: Apple Safari, Microsoft Internet Explorer, Google Chrome, Mozilla Firefox. If you do not use any of the browsers mentioned above, you will need to select the “cookies” option in the “Help” function to get information about the location of your cookie folder. Please note that if you choose to completely disable cookies, you may not be able to use all of our features.
4. Data retention period
DSTI keeps personal data only for the period required by its purpose, applicable legal duties and the establishment, exercise or defence of legal claims. Different services and records therefore have different periods.
DSTI Learn retention
- Academic committee minutes and decisions: 50 years from the committee sitting;
- Accounting records, including invoices and receipts: 10 years from the accounting document’s date;
- Disciplinary and expulsion records: 10 years after the student leaves; and
- Records with no applicable legal or claims-related retention: erased following a valid erasure request.
DSTI Learn identifies records that have passed their retention date for authorised human review; it does not delete records automatically. Historical records dating from 2015 are migrated only where continued retention remains appropriate.
Application System retention
- Ordinary in-progress applications: 730 days from the last authenticated save;
- Submitted applications: 1,825 days from submission;
- Operational test applications are retained for 7 days;
- Applicant document objects: no more than 1,825 days from their canonical upload time;
- Connector Lambda and API access logs are retained for 90 days;
- An exact signed change preview expires after 10 minutes;
- A Stage-1 Web hand-off token expires after 24 hours; and
- An application resume token expires after 730 days.
Terminal disposition
At an application record’s terminal date, access is denied immediately. DynamoDB Time to Live then removes the row asynchronously. Restricted point-in-time recovery may retain a restorable table state for up to 35 days after deletion; this is an operational recovery control, not an applicant-accessible archive. The same expiry is enforced independently in the active and retained governed release copies.
Document copies preserve the authoritative original upload time, so release copying does not restart retention. The active-release disposer removes all S3 object versions and delete markers when a document expires or its attributed application has expired or is absent. S3 lifecycle controls independently expire current objects, non-current versions and expired delete markers. AWS lifecycle and DynamoDB deletion are asynchronous, but access denial does not wait for physical deletion.
HubSpot and connector identity
Application-related HubSpot Contact and Deal records follow the corresponding application period: 730 days for an unsubmitted application and 1,825 days from submission. Independently consented marketing information follows the marketing relationship until withdrawal, after which DSTI retains only the minimum suppression evidence needed to honour that choice.
The Amazon Cognito connector identity remains while needed to access a retained application. It is deleted when the last linked application reaches its terminal date, or earlier following a valid erasure request where no overriding obligation applies. Provider-side physical deletion is completed within 30 days.
5. Users — rights over their personal data
In accordance with the Data Protection Act, the user has a right of access, rectification and deletion of data concerning him. He also has the possibility to object to the processing of his personal data for legitimate reasons. He can also send specific instructions to Data ScienceTech Institute regarding the use of his data after his death. Furthermore, the user can at any time withdraw his consent for the treatments that would be based on it, or request to no longer receive our communications relating to information, announcements, newsletters as well as invitations to events organised by Data ScienceTech Institute and its partners.
To exercise these rights, the user can send a request: by email to the following address: contact@dsti.institute or by mail to the following address:
DPO — Data ScienceTech Institute, 950 Route des Colles — 06410 Biot.
Data ScienceTech Institute may ask the user to provide proof of identity before responding to his request.
Students may exercise rights through DSTI Learn’s standard data-protection tools. On erasure, DSTI removes records unless Article 17(3) GDPR requires their retention, including relevant disciplinary, expulsion, academic committee and accounting records. Retained does not mean hidden: retained information remains included in a valid subject-access response for as long as DSTI keeps it.
Disconnecting the optional ChatGPT connector stops future connector calls but does not itself delete an Application System record, HubSpot record, Cognito identity or a conversation held under the user’s ChatGPT account. The user may continue the application through the secure DSTI Web application and may exercise access, rectification, restriction, objection, portability or erasure rights subject to applicable retention obligations.
6. Right to lodge a complaint with the CNIL
The user concerned by the processing of his personal data is informed of his right to lodge a complaint with a supervisory authority, namely the CNIL, if he considers that the processing of personal data concerning him is not in compliance with European data protection regulations, at the following address:
CNIL — Complaints Service, 3 Place de Fontenoy, TSA 80715 € 75334 Paris Cedex 07.
7. Accuracy of personal data
The user undertakes that the personal data concerning him communicated on the site are up-to-date, accurate, complete and unambiguous.
8. Communication of users — personal data
Data ScienceTech Institute commits to keep all personal data collected via the site and to share them only in certain circumstances and in accordance with the provisions of the applicable regulations.
Data ScienceTech Institute can notably give access to the personal data of users to third-party service providers, acting as subcontractors, to execute services related to the site and notably hosting, storage, analysis, data processing, database management or computer maintenance services. These providers act only on instruction from Data ScienceTech Institute and will have access to the personal data of users only to execute these services and will be subject to the same security and confidentiality obligations as Data ScienceTech Institute. Data ScienceTech Institute may also be required to communicate annually the data concerning the students of Data ScienceTech Institute to the Ministry of Higher Education and Research through the SISE information flows.
Furthermore, the personal data of the user can be shared with third parties for the following reasons: In the context of a merger or acquisition of all or part of Data ScienceTech Institute by a third party, which the user accepts;
In response to a judicial or administrative procedure of any kind or to law enforcement measures requested by the competent authorities;
To comply with legal obligations, to protect the rights and/or safety of an individual, to protect the rights and property of Data ScienceTech Institute, including the need to see this privacy policy respected, and to prevent fraud, security or technical problems.
Named service providers
DSTI is controller for the application and connector service. OpenAI separately governs the user’s ChatGPT account and conversation under the terms applicable to that user, and processes DSTI-provided customer data under the OpenAI Business/API Data Processing Addendum where applicable.
Information may also be processed by Amazon Web Services for application hosting, identity and operational infrastructure; HubSpot for admissions Contact and Deal records; Google or Microsoft when selected for federated identity or communications; Microsoft 365 for relevant DSTI communications and calendar delivery; and Stripe following a secure Web hand-off for a payment action. These providers process information under their applicable contractual and data-protection terms, and some may act independently for their own regulated purposes.
No applicant document and no payment-card detail is sent through the public ChatGPT connector.
9. Transfer of users — personal data
Personal data may be processed outside the European Economic Area where a service requires it. DSTI maintains a provider transfer map covering the service, data categories, region, data subjects, purpose, frequency, retention, provider role and applicable technical, organisational and contractual safeguards. Where an adequacy decision does not apply, DSTI relies on an applicable transfer mechanism such as the European Commission’s Standard Contractual Clauses and supplementary measures.
DSTI Learn and transcript verification
DSTI Learn’s application, database and cache run on Amazon Web Services Paris region (eu-west-3), within the EEA. Issued transcripts and attestations are stored in S3 in Paris and delivered to a holder of an unguessable verification token through the CloudFront global content-delivery network. A US-region revocation function processes only a random 128-bit revocation token and never document content.
These AWS transfers rely primarily on the EU–US Data Privacy Framework for covered US processing and on the 2021 Standard Contractual Clauses incorporated in the AWS Data Processing Addendum as a documented fallback. DSTI’s adopted Transfer Impact Assessment dated 24 July 2026 assesses the residual risk as low and requires review if the transfer basis, processing region, document content or special-category boundary changes.
OpenAI and the public connector
DSTI contracts with OpenAI Ireland Ltd for its EEA organisation and has accepted the current OpenAI Business/API Data Processing Addendum. The public app uses a global OpenAI project. When a user chooses the ChatGPT route, the information required for the conversation and connector action may be processed outside the European Economic Area under the user’s applicable ChatGPT terms and DSTI’s applicable OpenAI terms, including adequacy mechanisms and Standard Contractual Clauses for transfers where required.
This does not move DSTI’s canonical Web application, database, document store or HubSpot records into OpenAI. DSTI minimises connector responses and keeps documents, exact location, guardian information and payment credentials on the secure Web route.
10. Security and protection of users — personal data
DSTI applies administrative and technical measures appropriate to the risk, including role- and tenant-aware access control, verified-email ownership, least-privilege provider permissions, encryption in transit, protected document storage, redacted operational logs and fail-closed handling of ambiguous identity or provider failure.
DSTI Learn separates permissions for sensitive committee outcomes, deliberations and staff-only pastoral notes. Issued documents use a 128-bit unguessable token so that only a holder of the token can request verification.
The Application System uses short-lived, single-use confirmation authorities and backend-enforced access and retention controls. Protected applicant values remain on the secure Web application and appear only as redacted values through the connector.
11. Optional use of the DSTI Application connector in ChatGPT
DSTI offers an optional ChatGPT connector for selected Application System functions. The same application can be started, resumed and completed through the secure DSTI Web application. Choosing not to use ChatGPT does not prevent an applicant from applying to DSTI.
Use of the Application System is also governed by the Application System Terms of Use. OpenAI and ChatGPT provide the user-selected conversational surface; DSTI provides and governs the connector and canonical application service.
The connector lets an authenticated applicant, or a DSTI-approved study-abroad Agent acting for an applicant, view programme, route and intake choices; start or resume an application; view a minimised summary; request explanations of DSTI backend requirements; prepare and confirm an exact change; check readiness; and submit an eligible application after an exact preview and explicit confirmation.
ChatGPT is a conversational front end. It does not make admissions decisions, grant exemptions from DSTI rules or replace the canonical application record. It never treats an email address merely stated in a conversation as proof of identity or ownership.
Users should not type protected values, identity documents, passwords, one-time codes or payment-card details into a ChatGPT conversation. Information a user independently enters into a conversation is processed by OpenAI under the user’s applicable ChatGPT terms; it does not become a DSTI connector field merely because it appears in that conversation. OpenAI controls retention of the conversation under the user’s account, plan, workspace and data controls, and DSTI cannot delete it from the user’s OpenAI account.
12. Modification of the privacy policy
This Privacy Policy can be consulted on the site at any time. DSTI may update it when purposes, data categories, recipients, retention, processing regions or public capabilities change. The modified policy takes effect on its stated effective date. Last modified and effective: 24 July 2026.
13. Contacting Data ScienceTech Institute
If the user has questions or comments regarding this privacy policy, they can contact Data ScienceTech Institute at the following email address: contact@dsti.institute.