πŸ†• REFONTE β€” PRIVACY Β· remplace reprtoir.com/privacy (pΓ©rimΓ©e)  |  sous-traitants VΓ‰RIFIΓ‰S au code + rΓ©seau le 03/08  |  ⚠️ Γ  valider juridiquement (Dominique)
🎯 SEO v2  |  title : Privacy Policy | Reprtoir (24 car.)  |  meta : How Reprtoir collects, uses and protects your data across our website and app β€” the data we process, our sub-processors, your GDPR rights, and how to exercise them. (159 car.)

β€” AperΓ§u de CONTENU (structure & densitΓ©). Le design final = blocks shadcnblocks. Les [TO COMPLETE] = faits juridiques que seul Dominique fournit. β€” ← toutes les pages

Legal

Privacy Policy

This policy explains what personal data Reprtoir collects, why, who we share it with, and the rights you have over it β€” across both our website and our application.

Last updated: [TO COMPLETE β€” date] Β· Applies to reprtoir.com and the Reprtoir app.

Who we are

The Reprtoir service is operated by Reprtoir SAS, a company incorporated in France, which invoices customers and runs the service. Reprtoir SAS is the data controller for the personal data described here.

  • Registered office: 37 rue d'Antibes, 06400 Cannes, France
  • Company registration: RCS 989 488 713
  • Data protection requests: through our contact form.

The data we collect

We only collect what we need to run the website, provide the app, and support you.

When you visit our website

  • Usage and device data (pages viewed, approximate location, browser) via privacy-friendly analytics.
  • Anything you send us through the contact form or the support chat (your name, email, message).
  • Cookie and consent preferences.

When you use the app

  • Account data: name, email, password (hashed), organisation, role.
  • The content you upload and manage: catalog metadata, audio files, artwork, contracts, statements and related business data.
  • Billing data needed to take payment (handled by our payment processor β€” we never store full card numbers).
  • Product usage and error data to keep the service reliable.

Your audio and catalog remain yours. Your audio is never used to train AI models, and everything stays exportable at any time.

Why we process it, and on what legal basis

  • To provide the service you signed up for β€” legal basis: performance of our contract with you.
  • To take payment and prevent fraud β€” contract and our legitimate interest.
  • To support you and answer your messages β€” contract and legitimate interest.
  • To keep the platform secure and reliable (monitoring, error tracking) β€” legitimate interest.
  • To understand and improve usage via analytics β€” your consent, where required.
  • To meet our legal obligations (accounting, tax) β€” legal obligation.

Who we share data with (sub-processors)

We work with a small set of trusted providers to run Reprtoir. Each is bound by a data processing agreement compliant with Article 28 GDPR, and only processes data for the purpose below. We do not sell your personal data.

ProviderPurposeScopeData location
Amazon Web ServicesHosting & data processingAppπŸ‡ͺπŸ‡Ί EU β€” Ireland (prod), Paris (backups)
PostHogProduct analyticsBothπŸ‡ͺπŸ‡Ί EU
Cyanite (elceedee UG)Audio analysis / tagging (Audio AI feature)AppπŸ‡ͺπŸ‡Ί EU β€” Germany
FrontCustomer support & communicationBothπŸ‡ͺπŸ‡Ί EU β€” Ireland
CookiebotCookie consent managementWebsiteπŸ‡ͺπŸ‡Ί EU β€” Denmark
Revolut BusinessPayment β€” bank transfersAppπŸ‡ͺπŸ‡Ί EU β€” Lithuania (Revolut Bank UAB)
AttioCRM (customer & prospect data)BothπŸ‡¬πŸ‡§ UK β€” adequacy decision
StripePayment processing (PCI Level 1)AppEU (Stripe Payments Europe, Ireland) + US β€” SCC/DPF
CloudflareWebsite hosting & content deliveryWebsiteGlobal edge CDN β€” SCC
CloudinaryMedia & image deliveryAppUS β€” SCC/DPF
PostmarkTransactional emailAppUS β€” SCC/DPF
BugsnagError & stability monitoringBothUS β€” SCC/DPF
Kit (ConvertKit)Email marketing / newslettersBothUS β€” SCC/DPF

We keep this list current. Where a provider processes data outside the EU, we rely on appropriate safeguards (see below).

International data transfers

Your core data β€” your catalog, audio and business records β€” is hosted in the European Union (AWS Ireland/Paris). Our analytics (PostHog), audio tagging (Cyanite, Germany), support (Front, Ireland) and bank transfers (Revolut, Lithuania) also run in the EU. Our CRM (Attio) is UK-based, covered by the EU's adequacy decision.

A few providers process limited data in the United States β€” card payments (Stripe), transactional email (Postmark), media delivery (Cloudinary), error monitoring (Bugsnag) and email marketing (Kit). For these, we rely on appropriate safeguards: EU Standard Contractual Clauses (SCC) and, where applicable, the EU–US Data Privacy Framework (DPF). [safeguards to confirm per vendor]

How long we keep your data

We keep personal data only as long as necessary, then delete or anonymise it. We separate what lives inside the app from our own business records.

Data inside the app

Your account, your catalog (audio, metadata, artwork, contracts) and the backups that contain them are deleted 45 days after the final deletion notice.

Billing & business records

Invoicing and accounting data β€” including your company name, address and email β€” is kept for 10 years in our billing system and CRM. This meets our legal accounting obligations and lets us honour your choices (for example, not re-contacting an address that has unsubscribed).

Website & technical data

  • Website & product analytics (PostHog): 12 months.
  • Error & technical logs (Bugsnag): 90 days.
  • Cookie consent (Cookiebot): 12 months.
  • Support messages: kept for the duration of our business relationship.

You can ask us to delete your account and data at any time β€” see your rights.

Cookies & consent

We keep cookies to a minimum. We use:

  • Essential cookies β€” needed to sign in and use the site and app securely.
  • Analytics (PostHog, EU-hosted) β€” to understand usage across the website and app, only with your consent where required.

You control non-essential cookies through our consent banner (currently managed by Cookiebot), and you can change your choice at any time. We do not use advertising trackers such as Google Ads, Google Analytics or social-media pixels.

How we protect your data

Encryption in transit and at rest, EU-hosted infrastructure, continuous monitoring, least-privilege access and role-based permissions. Full detail on our Security page.

Your rights

Under the GDPR, you can:

  • Access the personal data we hold about you.
  • Correct data that is wrong or incomplete.
  • Delete your data ("right to be forgotten"), within legal limits.
  • Object to or restrict certain processing.
  • Receive your data in a portable format.
  • Withdraw consent at any time, without affecting past processing.

To exercise any of these, reach us through our contact form. You also have the right to lodge a complaint with your local supervisory authority β€” in France, the CNIL (cnil.fr).

Changes & contact

We may update this policy as our service evolves; we'll post the new version here and update the date at the top. For any privacy question, reach us through our contact form or by post at our registered office above.