This policy describes how Volade collects, uses, retains and protects your personal data, in accordance with Regulation (EU) 2016/679 (GDPR), the French data protection law of 6 January 1978 (as amended) and the CNIL (French data protection authority) guidelines. Our principle is simple: as little data as possible, and never sold or resold.
1. Data controller
- Controller: Volade — sole trader (Quentin Beltrame)
- Address: 2 rue du Tarn, 68200 Mulhouse, France
- Data protection contact: privacy@volade.com
Volade is the controller of the data collected on volade.com and through its products. Given the size of the business (micro-enterprise), no DPO has been appointed, in line with the exemptions provided by the GDPR and recalled by the CNIL; a dedicated contact point is operational: privacy@volade.com.
2. Personal data we collect
We only collect the data necessary for the operation of the service (principle of minimisation, Article 5.1(c) GDPR):
- Account: email address, password (hashed, never stored in clear), language and time zone.
- Payment: handled exclusively by Stripe (name, billing address, card data) — Volade never stores your credit card data.
- Devices: a hashed device identifier, used solely for licence management.
- Usage: anonymous and aggregated usage statistics (features used, performance) to improve the tools.
- Browsing: language preferences.
- Communications: emails exchanged with support and the Volade team.
3. Data we do NOT collect
- Your full browsing history (processed locally on your device).
- The content of the pages or websites you visit.
- Data from your forms, messaging or content processed by our tools.
- Your precise geolocation.
- No sensitive data (health, religion, orientation, political opinions…).
Our extensions and tools operate locally: most of your files and content never leave your device.
4. Purposes and legal bases
- Providing the premium service and managing licences → performance of contract (Art. 6.1(b) GDPR).
- Managing subscription and invoicing → performance of contract + legal obligation (Art. 6.1(b) and (c)).
- Support and assistance → legitimate interest (Art. 6.1(f)).
- Improving our tools (anonymous statistics) → legitimate interest (Art. 6.1(f)).
- Newsletter and offers (if you subscribe) → consent (Art. 6.1(a)), revocable at any time.
- Evidence of acceptance of the Terms → proof and legal defence (Art. 6.1(f)).
- Legal compliance (accounting, tax) → legal obligation (Art. 6.1(c)).
5. Processors and data sharing
We never sell, rent or share your data for commercial purposes. Only strictly necessary processors, bound by contract in accordance with Article 28 GDPR, may process data:
- Payment: Stripe Payments Europe Ltd — licensed in the EU, PCI-DSS compliant.
- Hosting: Oracle Cloud Infrastructure (OCI), Paris (France) region, EU.
- Transactional/newsletter emails: [TO COMPLETE — GDPR-compliant provider].
- Analytics: no third-party advertising measurement tool; internal anonymised audience measurement.
Outside the EU: we favour European processors. Any cross-border transfer is governed by Standard Contractual Clauses (SCCs) of the European Commission and/or an adequacy decision (Articles 45-46 GDPR).
6. Retention periods
- Account data: for the life of the account and up to 1 year after closure in the event of a dispute.
- Invoicing/accounting data: 10 years (accounting and tax obligations).
- Anonymous statistics: limited to the strict minimum, without identifiers.
- Support emails: 3 years from the last exchange.
- Anonymised audience measurement tracer (where applicable): 13 months (data kept for a maximum of 25 months), in line with CNIL recommendations.
7. Security
We implement technical and organisational measures proportionate to the risks: TLS encryption in transit (HTTPS across the entire site), strong password hashing (bcrypt/argon2), restricted and revocable access management, limited logging, encrypted backups and regular permission reviews. Security audits and updates are performed on an ongoing basis.
8. Transfers outside the EU
All data is stored in the European Union (Oracle Cloud, Paris region). Except for an explicitly agreed exception, no transfer outside the EU is made. Should this change, Volade would ensure compliance with Article 46 GDPR (SCCs, binding corporate rules) and inform you accordingly.
9. Your rights
Pursuant to Articles 15 to 22 GDPR, you have the following rights:
- Access to your data;
- Rectification of inaccurate information;
- Erasure ("right to be forgotten");
- Restriction of processing;
- Objection to processing (notably to prospecting);
- Portability of your data;
- Withdraw consent at any time;
- Give instructions on the fate of your data after your death.
To exercise these rights: privacy@volade.com (or directly from your account for profile data). We respond within 1 month, extendable by 2 months for complex requests, in accordance with Article 12 GDPR.
If you consider that your rights are not respected, you may lodge a complaint with the CNIL (3 place de Fontenoy, 75007 Paris — www.cnil.fr) or with the supervisory authority of your country of residence in the EU.
10. Automated decisions and profiling
Volade does not take any automated decision producing legal effects on you. Unless stated otherwise, displayed prices are not personalised by algorithm. No advertising profiling is performed.
11. Minors
Volade services are intended for adults capable of contracting. Emancipated minors may use the service; creating an account by a non-emancipated minor requires the consent of a holder of parental authority. We do not knowingly collect data from children under the age of 15.
12. Cookies and tracking technologies
The website does not place any advertising or profiling cookie. The only cookies placed are strictly necessary for its operation (language preferences, session); where applicable, an exempted anonymised audience measurement may be implemented, in accordance with the CNIL guidelines and EU Directive 2002/58/EC (ePrivacy). No consent banner is displayed: no consent is required. See our Cookie Policy.
13. Data breach (notification)
In the event of a data breach likely to create a risk to your rights and freedoms, we will notify the CNIL within 72 hours (Art. 33 GDPR) and inform you directly if the risk is high (Art. 34 GDPR).
14. Changes to this policy
This policy may be updated. Any change will be published on this page with a new date. Significant changes will be notified by email where possible, allowing you to renew your consent when required.
15. Contact
For any question about this policy or your data: privacy@volade.com. We respond within 1 month maximum.