Privacy policy
Data controller
The controller of your data is [ENTITÉ LÉGALE], [ADRESSE COMPLÈTE]. For any question regarding your data: [EMAIL RGPD]. Data Protection Officer (DPO): [DPO — name / e-mail, if any].
Data collected
Account data (e-mail, name, company, phone), KYC verification documents, listing content, messages, offers and appointments, technical logs.
Purposes
Operate the marketplace (listings, messaging, offers, appointments), verify counterparties (KYC), ensure security and meet legal obligations.
Legal bases
Performance of the contract (providing the marketplace, messaging, offers, appointments); legal obligation and legitimate interest (KYC checks, security, fraud prevention, regulatory retention); consent (analytics and newsletter communications, revocable at any time).
Recipients and processors
Your data is accessible to authorized CAP10 staff and our technical processors: Supabase (database hosting and authentication), Vercel Inc. (application hosting), Resend (transactional and newsletter e-mail delivery), Google (reCAPTCHA, Analytics/Tag Manager under consent). No data is sold to third parties.
Transfers outside the EU
Some processors may host or process data outside the European Union (notably in the United States). Such transfers are governed by appropriate safeguards (European Commission Standard Contractual Clauses and/or certification mechanisms).
Retention
KYC verification documents are kept for 5 years after the end of the relationship, in line with compliance requirements. Other data is kept for the duration of the contractual relationship.
Your rights
Under the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw consent at any time and to lodge a complaint with the competent supervisory authority. Some data (KYC documents) is retained to meet our legal obligations even after account closure. To exercise your rights: [EMAIL RGPD].
Security
Encryption in transit (HTTPS/TLS) and at rest, access partitioning via row-level security (RLS), private buckets for KYC documents, admin access logging, and strict access controls.
Updates
This policy may be updated. In case of substantial change, registered users will be notified.