⚠️ Draft to be reviewed by a lawyer before commercial launch (DPO recommendation).
For data relating to your manager account and billing, the data controller is [TO COMPLETE: publisher].
For end-customer data entered through the service (bookings, contacts, staff), each business is the controller; MonComptoir acts as a processor within the meaning of Article 28 GDPR.
Account: email, password (stored hashed), business name.
Billing: handled by Stripe — the publisher stores no card data.
Business data entered by the manager: bookings (name, email, phone, note), contacts, staff and their documents.
Technical data: connection logs and audience measurement.
Service provision and account management: performance of the contract.
Billing and accounting: legal obligation.
Marketing emailing to contacts: prior consent, collected by the business.
Security and service improvement: legitimate interest.
Host (European Union): [TO COMPLETE].
Stripe (payment): data may be transferred outside the EU, framed by Standard Contractual Clauses and the Data Privacy Framework.
Resend (email sending). PostHog (audience measurement, EU-hosted).
No data is sold to third parties.
Account: for the duration of the contract, then deletion.
Billing records: 10 years (accounting obligation).
Bookings: 13 months after the event. Contacts: until consent withdrawal or account deletion. Technical logs: 12 months.
You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time.
Export and deletion of your data are available directly in your account Settings.
To exercise your rights: contact@moncomptoir.app. You may lodge a complaint with the CNIL (www.cnil.fr).
Passwords are hashed, traffic is encrypted (HTTPS), hosting is in the EU, and each business's data is strictly isolated.
Details of cookies are set out in the Cookie policy.
Last updated: [TO COMPLETE].