EXAUTHYS

Legal pages

Privacy policy

Personal data processing in compliance with the GDPR: purposes, retention, exercisable rights.

Last updated: 24 May 2026

⚠️ The French version is legally authoritative. Other versions are provided as a courtesy translation.

This policy describes how EXAUTHYS collects and processes your personal data. You may exercise your rights at any time via your account or by emailing rgpd@exauthys.com.

1. Data controller

The data controller is EXAUTHYS, headquartered in Cayenne, French Guiana (full details in the Legal Notice). Our Data Protection Officer (DPO) can be reached at rgpd@exauthys.com.

2. Data collected & purposes

2.1 Account creation & identification

Last name, first name, email, password (bcrypt cost 12 hash), phone number, preferred language, and date of birth where relevant. Legal basis: performance of contract (GDPR Art. 6.1.b). Retention: for the lifetime of the account plus 3 years (commercial limitation).

2.2 Bookings & payments

Booking history, amounts, chosen Providers, dates. EXAUTHYS never stores card data in plain text: card numbers are tokenised by the PCI-DSS-certified payment processor (Stripe as the first implementation). Retention: 10 years for accounting data (French Commercial Code Art. L.123-22).

2.3 Loyalty programme

Point balance and transaction history (EARN / SPEND / BONUS / EXPIRE). Retention: account lifetime. Points themselves expire automatically 3 years after issuance.

2.4 Communications & marketing

Email address and communication preferences. Legal basis: explicit consent (GDPR Art. 6.1.a), revocable at any time via the preferences centre or the unsubscribe link in every email. Retention: until consent is withdrawn.

2.5 Security & audit log

IP address, user agent, timestamps of connections, failed logins and sensitive actions (payment, Provider bank account change). Legal basis: legitimate interest in protecting the platform (GDPR Art. 6.1.f). Retention: 5 years (aligned with anti-fraud obligations, French Monetary and Financial Code L.561-12).

2.6 Providers — administrative information

SIRET, IBAN/BIC (AES-256 encrypted), document verification artefacts. Legal basis: legal obligation (identity verification, anti-money-laundering) and performance of the partnership contract.

3. Cookies & trackers

Details on cookies in use (strictly necessary, analytics, marketing) are documented in the Cookie Policy available in the summary. No analytics or marketing cookies are dropped before your explicit consent via the CNIL banner.

4. Recipients & sub-processors

Your data is accessible only to authorised EXAUTHYS staff and to the following sub-processors, bound by a GDPR-Art.-28 contract:

  • Stripe (payment processor, PCI-DSS Level 1) — for payment processing;
  • Twilio — for authentication SMS delivery;
  • AWS / Scaleway — for hosting and S3 storage of media;
  • Nodemailer + SMTP server — for transactional emails.

5. Transfers outside the EU

EXAUTHYS hosts its data in the European Union. Any transfer to a third country (for example when booking with a Provider located outside the EU) is governed by the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914) or by an adequacy decision where applicable.

6. Your rights

You may exercise at any time the following rights:

  • Access (Art. 15) — obtain a copy of your data;
  • Rectification (Art. 16) — correct inaccurate data;
  • Erasure / right to be forgotten (Art. 17) — subject to legal retention obligations;
  • Restriction of processing (Art. 18);
  • Portability (Art. 20) — receive your data in a structured, machine-readable format;
  • Objection (Art. 21) — to processing based on legitimate interest or to marketing profiling;
  • Post-mortem instructions (Art. 40-1 French Data Protection Act).

You can exercise these rights from the “Privacy” tab of your account or by emailing rgpd@exauthys.com. EXAUTHYS will reply within one month (extendable by two months for complex requests, GDPR Art. 12.3). You also have the right to lodge a complaint with the CNIL (www.cnil.fr).

7. Security

EXAUTHYS implements appropriate technical and organisational measures: TLS 1.3 encryption in transit, AES-256 at-rest encryption for sensitive data (IBAN/BIC), multi-factor authentication on administrative accounts, rate limiting and suspicious login detection, and a comprehensive audit log of sensitive operations.

8. Minors

Registration is prohibited for minors under 15. Between 15 and 18, registration requires the consent of a holder of parental authority. EXAUTHYS reserves the right to ask for proof and to close any non-compliant account without notice.

9. Changes

Any substantive change to this policy is notified to users by email at least 30 days before it takes effect. The last update date appears at the top of the page.

Contact the DPO

Postal address :
DPO EXAUTHYS — Cayenne, French Guiana
Supervisory authority :
CNIL — www.cnil.fr