Privacy Policy

1. Data controller

The controller responsible for processing personal data collected through the NACarnet Application is Aurélien Le Rouillé, a sole proprietorship registered under SIRET 108 242 637 00016, whose registered office is located at 61 rue de Lyon, 75012 Paris, France. Contact: support@nacarnet.fr.

No Data Protection Officer (DPO) has been appointed to date, as the Publisher does not meet the thresholds that would make such an appointment mandatory (art. 37 GDPR). This will be reassessed should the Publisher's headcount or data-processing volume change significantly.

2. Data collected

CategoryExamplesMain purpose
Identity and contact detailsLast name, first name, e-mail addressAccount creation and management
Professional dataSIRET numberAccess to the Professional tier, issuing the subscription confirmation
User contentAnimal records (species, morph, photos, care history), posts, comments, private messages, attachmentsOperation of the care journal and the community
LocationDeclared city and postal code (assisted entry, approximate precision)Pre-filling Marketplace listings
Financial dataPayment and subscription confirmation history (once real payment integration is in place)Accounting
Technical identifiersAccount identifier, push notification tokenService operation, notifications
Diagnostic dataCrash reports (Sentry), application version, platformService stability and security

No human health data, nor any special category of data within the meaning of Article 9 GDPR, is collected. Animal health data (a reptile's state of health) does not fall within the special categories of data under the GDPR, which applies only to natural persons.

3. Purposes and legal bases

PurposeLegal basis (art. 6 GDPR)
Account creation and management, provision of the servicePerformance of a contract (Terms of Use)
Billing of subscriptions and purchasesPerformance of a contract / legal obligation (accounting)
Community moderation, handling of reportsLegitimate interest of the Publisher and of users (community safety)
Verification of Professional accounts (SIRET)Performance of a contract / legitimate interest (fraud prevention)
Sending transactional e-mails (confirmation, password reset, subscription confirmations)Performance of a contract
Push notifications (care reminders, messaging)Consent (can be enabled/disabled in settings)
Crash reports and technical diagnosticsLegitimate interest (service security and stability)
Internal usage statisticsLegitimate interest

4. Recipients and processors

Data is accessible to the Publisher's own team (support, moderation) under a principle of least technical privilege (per-user segregation enforced at database level). The following technical providers act as processors within the meaning of Article 28 GDPR:

ProcessorRoleData location
Supabase Pte. Ltd.Database hosting and authenticationDatabase physically hosted in the European Union (eu-west-3 region, Paris); legal entity registered in Singapore — Supabase's DPA is publicly available and provides its own standard contractual clauses for support access from outside the EU
Plus Five Five, Inc. (Resend)Sending transactional e-mailsUnited States (San Francisco) — public DPA available (resend.com/legal/dpa)
Functional Software, Inc. (Sentry)Crash reports and diagnosticsUnited States (San Francisco) — a standard DPA offered by Sentry
Vercel Inc.Hosting of the admin back-office and of the web authentication portalUnited States (Covina, California) — public DPA available
Cloudflare, Inc.Technical processing of e-mail and notification deliveryUnited States (San Francisco) — public DPA available

No data is sold or transferred to third parties for commercial or advertising purposes. In accordance with Article 28 GDPR, the Publisher puts a Data Processing Agreement in place with each of these providers — the addresses and locations above come from each provider's public legal pages (see their respective websites).

5. Transfers outside the European Union

The main database is physically hosted within the European Union (Supabase, eu-west-3 region, Paris). Four providers (Resend, Sentry, Vercel, Cloudflare) are US companies that may process data outside the EU (in particular e-mail delivery metadata, crash reports, and back-office technical logs); Supabase Pte. Ltd. is also a legal entity registered in Singapore, which may imply support access from outside the EU even though storage itself remains in France. In all cases, such transfers must be covered by the European Commission's standard contractual clauses (each provider listed offers a standard Data Processing Agreement incorporating this mechanism) or any other transfer mechanism recognised under the GDPR. The existence of these DPAs on the provider side is public; their execution and effective activation on the NACarnet account are subject to ongoing follow-up by the Publisher.

6. Retention period

See the Data Retention Policy, which details the applicable retention periods per data category.

7. Rights of the data subject

In accordance with Articles 15 to 21 GDPR, every user has the following rights over their personal data:

These rights may be exercised by writing to support@nacarnet.fr, or directly from the Application's settings for account deletion. The Publisher will respond within one month at most, which may be extended by two months for complex requests, with the user informed in that case.

8. Complaint to the CNIL

Any user who considers that the processing of their data does not comply with applicable regulations has the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL) — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — or with the supervisory authority of their EU member state of residence.

9. Data security

See the Security Policy, which details the technical and organisational measures implemented.

Last updated: September 14, 2026