Legal

Privacy Policy

Last updated: January 2025 — This policy explains how we collect, use, and protect your personal data, in accordance with the General Data Protection Regulation (GDPR) and applicable French law.

1

Who is responsible for your data?

SuperAslan France, registered in France, is the data controller.

Contact: confidentialite@superaslan.com

2

What data do we collect?

We collect information you provide directly (name, address, contact details, project descriptions, payment information) as well as data generated by your use of the platform (browsing activity, device identifiers, message history with professionals).

3

Why do we use your data?

Your data is used to:

  • Create and manage your account
  • Connect you with suitable professionals
  • Process your payments securely
  • Send you service-related communications
  • Improve our platform and meet our legal obligations
4

Who has access to your data?

Your data may be shared with professionals you contact via the platform, our payment provider, and our technical partners (hosting, analytics) bound by strict data processing agreements. We never sell your data to third parties.

5

How long do we retain your data?

Account data is retained for the duration of your relationship with us, then for 3 years after your last activity.

Transaction data is retained for 10 years in accordance with French accounting law.

6

Your rights

Under the GDPR, you have the right to access, rectify, erase, and port your data (in certain specific cases), as well as the right to object to certain processing activities. To exercise your rights, contact us at confidentialite@superaslan.com. You may also lodge a complaint with the CNIL (cnil.fr).

7

Cookies

We use cookies that are essential to the platform’s operation and, with your consent, analytical cookies to understand how our services are used. You can manage your preferences at any time from the footer of our website.

8

Security

We apply technical and organisational measures in line with industry standards to protect your data against unauthorised access, loss, or disclosure. Payments are processed via PCI-DSS certified providers.