Privacy Policy

2026-08-23 · v1.0.0

Version 1.0.0 — last updated on 23 August 2026

1. Who is responsible for your data?

The data controller is the publisher of the FolioFinance service available at foliofinance.fr.

For any question relating to your personal data or to exercise your rights: rgpd@foliofinance.fr.

No data protection officer (DPO) has been appointed, as this appointment is not mandatory given the nature and volume of the processing carried out.

2. What data do we process, why, and on what basis?

Processing Data concerned Legal basis Retention
Account creation and management First name, last name, e-mail address, job title (optional), password (stored as a non-reversible hash), creation date Performance of the contract (Art. 6.1.b GDPR) Lifetime of the account, then 30 days
Authentication and session security 15-minute access token (never written to the browser), refresh token carried by a cookie, with rotation and reuse detection Legitimate interest — service security (Art. 6.1.f) 7 days (lifetime of the refresh token)
Portfolio editing and hosting Written content, section structure, chosen template, public identifier (slug), publication status, page-protection password (non-reversible hash) Performance of the contract Lifetime of the account, then 30 days
Voluntarily published contact details E-mail address, LinkedIn profile, phone number entered in the portfolio's contact block Consent (Art. 6.1.a) — entering and publishing them is a voluntary action Until withdrawn by the user
Uploaded files Images and documents, with their technical metadata (name, size, type) Performance of the contract Lifetime of the account, then 30 days
AI writing assistance Text excerpts from the portfolio transmitted to the model, monthly usage counter Performance of the contract, at the user's request Content not retained by the provider beyond processing; counter reset monthly, kept at most 12 months
Audience of a published portfolio Aggregate view counter and date of last visit — no visitor is identified, no IP address is associated Legitimate interest — informing the portfolio owner (Art. 6.1.f) Lifetime of the account
Visits to a published portfolio Truncated IP address, date and time, page visited (technical security logs) Legitimate interest — security and abuse prevention (Art. 6.1.f) 6 months
Rendered copy of published pages Technical cache of published content, regenerated on each change Performance of the contract 30 days at most; purged on unpublishing or deletion
Tracker consent Choice expressed, date, scope Legal obligation (Art. 82 of the French Data Protection Act) 6 months
Server technical logs Error messages and technical events, without portfolio content or contact details Legitimate interest — keeping the service operational (Art. 6.1.f) 90 days
Acceptance of the terms Accepted version, date, IP address Legal obligation — proof of contractual consent Lifetime of the account + 5 years
Data-rights requests (export…) Date and IP address of the request Legal obligation — proof of the response provided Lifetime of the account + 5 years

No data is used for commercial prospecting, profiling, targeted advertising or resale. No audience-measurement tool is installed.

3. Sensitive data

The service is not intended to process sensitive data within the meaning of Article 9 GDPR. You are asked not to publish any in your portfolio.

4. Who has access to your data?

Your data is only accessible to the publisher and to the following providers, acting as processors on its behalf:

Provider Role Location of processing
OVH SAS Hosting of the application, the database and the uploaded files (files are stored on the same server as the application — no separate storage provider), and delivery of service e-mails France
Mistral AI Generation of writing suggestions, when the AI features are enabled France (European Union)

Each processor is bound by a contract compliant with Article 28 GDPR. No transfer outside the European Union is necessary for the operation of the service.

Voluntary publication: when you publish your portfolio, the content and contact details it contains become accessible to anyone who has its address, and may be indexed by search engines if you have allowed it. This disclosure results from your decision and does not amount to a communication of data by the publisher to a third party.

5. Third-party services embedded in portfolios

Portfolios may display content hosted by Microsoft (Power BI, Office Online, OneDrive), Google (Looker Studio, Google Docs) and Tableau (Salesforce). This content is loaded from those companies' servers, which may on that occasion set trackers and collect connection data on their own behalf, as independent data controllers.

For this reason, these embeds are only loaded after your explicit consent: a placeholder is displayed in their place until you click to activate them. See the Cookie Policy.

6. How long do we keep your data?

Retention periods are set out in the table in Section 2. At the end of these periods, the data is deleted or irreversibly anonymised.

When you delete your account, your data is immediately removed from production (account, portfolio, files and rendered copies) and permanently erased from any backups within a maximum of 30 days. Data kept under a legal obligation (proof of acceptance of the terms, security logs) is kept only for the period provided for, with restricted access.

An account with no sign-in for 24 months receives an information e-mail; failing a response within 30 days, it is deleted.

7. Your rights

You have the following rights:

To exercise these rights: rgpd@foliofinance.fr. A response will be provided within one month, extendable by two months for complex requests. Proof of identity may be requested in case of reasonable doubt.

If, after contacting us, you consider that your rights are not being respected, you may lodge a complaint with the CNIL: CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr

8. Security

The following measures are in place: encryption of exchanges (HTTPS/TLS), passwords stored as salted hashes (bcrypt), short-lived session tokens with rotation and reuse detection, httpOnly session cookies, security headers (Content-Security-Policy, HSTS), systematic server-side input validation, rate limiting on sensitive routes, and regular dependency updates.

In the event of a data breach likely to result in a high risk to your rights and freedoms, you will be informed as soon as possible, and the CNIL will be notified within 72 hours.

9. Changes to this policy

Any substantial change is notified by e-mail and flagged in the service. The version in force is the one published on this page.