Privacy Policy (GDPR)
Last updated: April 2026
This Privacy Policy explains how Soaria (“we”, “us”, “our”) collects and processes personal data when you use our website and platform (the “Service”).
1) Data controller
The data controller is Soaria.
Contact: contact@soaria.fr
Address: 11 avenue Paul Verlaine, 38100 Grenoble, France
2) Personal data we process
Depending on how you use the Service, we may process:
- Account data: email, first name, last name, profile information.
- Usage data: technical logs, IP address, session identifiers, pages viewed, navigation events.
- Communications: messages to support and any attachments.
- Service emails: data strictly necessary to send emails (e.g., email address, sending/deliverability metadata).
- Billing data: payment and invoicing-related data (we do not store full payment card details).
- Uploaded documents: documents you upload to the Service, which may include sensitive information (e.g., identity documents, financial documents, legal/HR documents, project documents).
3) Purposes and legal bases
We process personal data for the following purposes:
- Provide the Service (account creation, access, features, support): performance of a contract.
- Customer relationship and support: performance of a contract / legitimate interests.
- Service security (fraud prevention, anomaly detection, security logs): legitimate interests.
- Billing and statutory obligations: legal obligation.
- Analytics: legitimate interests and/or consent where required by applicable rules.
4) Where your data is stored (hosting and location)
We host and store Service data in the European Union:
- Application servers: Hetzner (Helsinki, Finland).
- Database: Supabase (Postgres) — EU region.
- User documents: Supabase Storage (S3-compatible) — EU region.
We aim to keep processing within the EU. If a transfer outside the EU becomes necessary, we will implement appropriate safeguards as required by the GDPR (e.g., Standard Contractual Clauses) and inform you.
5) Sensitive documents: what we do with them
Documents you upload may contain highly sensitive information (identity, financial situation, contractual information).
We process them only to:
- allow you to store, view, organize, and share them within the Service;
- provide platform functionality (e.g., creating/structuring deliverables based on information you submit or upload);
- ensure Service security and continuity.
We do not have external vendors analyze your uploaded document content (no external OCR/AI vendor) beyond the hosting/storage and technical transit required to operate the Service.
6) Recipients and processors
Your data may be accessed:
- Internally: by authorized Soaria staff, on a need-to-know basis.
- By our processors (depending on the Service):
- Hetzner Online GmbH (application hosting in Helsinki, Finland),
- Supabase (database and file storage — EU region),
- Stripe (payments),
- Resend (transactional and service email delivery),
- Umami (analytics).
- GitHub (source code hosting and version control; technical data related to development and repository access).
We select providers that offer adequate safeguards and we put in place processor agreements where required.
7) Retention
We keep personal data only for as long as necessary for the purposes described above.
Unless stated otherwise, we apply the following principles (to be adjusted to your needs):
- Account data: for the lifetime of the account, then deleted/anonymized after closure, subject to legal obligations.
- Documents: for the lifetime of the account, then deleted after closure following a grace period [to be defined].
- Billing data: retained as required by law (e.g., accounting).
- Technical/security logs: retained for a limited period [to be defined] unless needed for security.
8) Security
We implement appropriate security measures, including:
- access control and least-privilege permissions;
- encryption in transit (HTTPS/TLS);
- monitoring and incident prevention measures;
- backups and recovery procedures.
We also undergo regular audits by cybersecurity experts to assess and improve our security posture.
No system is completely secure; we cannot guarantee absolute security, but we strive to reduce risks as much as possible.
9) Cookies and analytics
We may use analytics technologies to understand Service usage and improve it.
Depending on configuration, some analytics tools can operate without cookies, or may require your consent. When consent is required, we implement an information/consent mechanism.
10) Your rights (GDPR)
You have the following rights: access, rectification, erasure, restriction, objection, portability (as applicable).
To exercise your rights: contact@soaria.fr.
You may also lodge a complaint with the CNIL (France).
11) Updates to this policy
We may update this policy. The last updated date appears at the top of this page. If changes are material, we may notify you through the Service.