CAP10JETS

Privacy policy

Data controller

The controller of your data is [ENTITÉ LÉGALE], [ADRESSE COMPLÈTE]. For any question regarding your data: [EMAIL RGPD]. Data Protection Officer (DPO): [DPO — name / e-mail, if any].

Data collected

Account data (e-mail, name, company, phone), KYC verification documents, listing content, messages, offers and appointments, technical logs.

Purposes

Operate the marketplace (listings, messaging, offers, appointments), verify counterparties (KYC), ensure security and meet legal obligations.

Legal bases

Performance of the contract (providing the marketplace, messaging, offers, appointments); legal obligation and legitimate interest (KYC checks, security, fraud prevention, regulatory retention); consent (analytics and newsletter communications, revocable at any time).

Recipients and processors

Your data is accessible to authorized CAP10 staff and our technical processors: Supabase (database hosting and authentication), Vercel Inc. (application hosting), Resend (transactional and newsletter e-mail delivery), Google (reCAPTCHA, Analytics/Tag Manager under consent). No data is sold to third parties.

Transfers outside the EU

Some processors may host or process data outside the European Union (notably in the United States). Such transfers are governed by appropriate safeguards (European Commission Standard Contractual Clauses and/or certification mechanisms).

Retention

KYC verification documents are kept for 5 years after the end of the relationship, in line with compliance requirements. Other data is kept for the duration of the contractual relationship.

Your rights

Under the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw consent at any time and to lodge a complaint with the competent supervisory authority. Some data (KYC documents) is retained to meet our legal obligations even after account closure. To exercise your rights: [EMAIL RGPD].

Security

Encryption in transit (HTTPS/TLS) and at rest, access partitioning via row-level security (RLS), private buckets for KYC documents, admin access logging, and strict access controls.

Cookies and trackers

Strictly necessary cookies (session, security, language preference, consent) are set without consent. Analytics and marketing trackers (Google Analytics 4, Google Tag Manager) are only set after your consent via the banner, using Consent Mode v2. Google reCAPTCHA v3 is used on our forms to prevent abuse (legitimate interest). You can accept, refuse or limit trackers at any time via the consent banner.

Updates

This policy may be updated. In case of substantial change, registered users will be notified.

Log inSign up