1. Data controller
The controller responsible for processing personal data collected through the NACarnet Application is Aurélien Le Rouillé, a sole proprietorship registered under SIRET 108 242 637 00016, whose registered office is located at 61 rue de Lyon, 75012 Paris, France. Contact: support@nacarnet.fr.
No Data Protection Officer (DPO) has been appointed to date, as the Publisher does not meet the thresholds that would make such an appointment mandatory (art. 37 GDPR). This will be reassessed should the Publisher's headcount or data-processing volume change significantly.
2. Data collected
| Category | Examples | Main purpose |
|---|---|---|
| Identity and contact details | Last name, first name, e-mail address | Account creation and management |
| Professional data | SIRET number | Access to the Professional tier, issuing the subscription confirmation |
| User content | Animal records (species, morph, photos, care history), posts, comments, private messages, attachments | Operation of the care journal and the community |
| Location | Declared city and postal code (assisted entry, approximate precision) | Pre-filling Marketplace listings |
| Financial data | Payment and subscription confirmation history (once real payment integration is in place) | Accounting |
| Technical identifiers | Account identifier, push notification token | Service operation, notifications |
| Diagnostic data | Crash reports (Sentry), application version, platform | Service stability and security |
No human health data, nor any special category of data within the meaning of Article 9 GDPR, is collected. Animal health data (a reptile's state of health) does not fall within the special categories of data under the GDPR, which applies only to natural persons.
3. Purposes and legal bases
| Purpose | Legal basis (art. 6 GDPR) |
|---|---|
| Account creation and management, provision of the service | Performance of a contract (Terms of Use) |
| Billing of subscriptions and purchases | Performance of a contract / legal obligation (accounting) |
| Community moderation, handling of reports | Legitimate interest of the Publisher and of users (community safety) |
| Verification of Professional accounts (SIRET) | Performance of a contract / legitimate interest (fraud prevention) |
| Sending transactional e-mails (confirmation, password reset, subscription confirmations) | Performance of a contract |
| Push notifications (care reminders, messaging) | Consent (can be enabled/disabled in settings) |
| Crash reports and technical diagnostics | Legitimate interest (service security and stability) |
| Internal usage statistics | Legitimate interest |
4. Recipients and processors
Data is accessible to the Publisher's own team (support, moderation) under a principle of least technical privilege (per-user segregation enforced at database level). The following technical providers act as processors within the meaning of Article 28 GDPR:
| Processor | Role | Data location |
|---|---|---|
| Supabase Pte. Ltd. | Database hosting and authentication | Database physically hosted in the European Union (eu-west-3 region, Paris); legal entity registered in Singapore — Supabase's DPA is publicly available and provides its own standard contractual clauses for support access from outside the EU |
| Plus Five Five, Inc. (Resend) | Sending transactional e-mails | United States (San Francisco) — public DPA available (resend.com/legal/dpa) |
| Functional Software, Inc. (Sentry) | Crash reports and diagnostics | United States (San Francisco) — a standard DPA offered by Sentry |
| Vercel Inc. | Hosting of the admin back-office and of the web authentication portal | United States (Covina, California) — public DPA available |
| Cloudflare, Inc. | Technical processing of e-mail and notification delivery | United States (San Francisco) — public DPA available |
No data is sold or transferred to third parties for commercial or advertising purposes. In accordance with Article 28 GDPR, the Publisher puts a Data Processing Agreement in place with each of these providers — the addresses and locations above come from each provider's public legal pages (see their respective websites).
5. Transfers outside the European Union
The main database is physically hosted within the European Union (Supabase, eu-west-3 region, Paris). Four providers (Resend, Sentry, Vercel, Cloudflare) are US companies that may process data outside the EU (in particular e-mail delivery metadata, crash reports, and back-office technical logs); Supabase Pte. Ltd. is also a legal entity registered in Singapore, which may imply support access from outside the EU even though storage itself remains in France. In all cases, such transfers must be covered by the European Commission's standard contractual clauses (each provider listed offers a standard Data Processing Agreement incorporating this mechanism) or any other transfer mechanism recognised under the GDPR. The existence of these DPAs on the provider side is public; their execution and effective activation on the NACarnet account are subject to ongoing follow-up by the Publisher.
6. Retention period
See the Data Retention Policy, which details the applicable retention periods per data category.
7. Rights of the data subject
In accordance with Articles 15 to 21 GDPR, every user has the following rights over their personal data:
- Right of access: to obtain confirmation that their data is being processed and to obtain a copy of it;
- Right to rectification: to have inaccurate or incomplete data corrected;
- Right to erasure: to request deletion of their data, under the conditions described in the Account Deletion Policy;
- Right to restriction of processing;
- Right to data portability: to receive their data in a structured, commonly used, machine-readable format;
- Right to object, in particular to processing based on legitimate interest;
- Right to withdraw consent at any time where processing is based on it (push notifications), without retroactive effect;
- Right to define directives regarding the fate of their data after death (art. 85 of the French Data Protection Act).
These rights may be exercised by writing to support@nacarnet.fr, or directly from the Application's settings for account deletion. The Publisher will respond within one month at most, which may be extended by two months for complex requests, with the user informed in that case.
8. Complaint to the CNIL
Any user who considers that the processing of their data does not comply with applicable regulations has the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL) — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — or with the supervisory authority of their EU member state of residence.
9. Data security
See the Security Policy, which details the technical and organisational measures implemented.
Last updated: September 14, 2026