GDPR · Article 13/14

Privacy Policy

Last updated: 23 June 2026

Navigating France ("we", "us") provides a guided checklist, document repository, and a guided assistant for people moving to or living in France. This Privacy Policy explains what personal data we process, why, on what legal basis, how long we keep it, and how you can exercise your rights under the General Data Protection Regulation (Regulation (EU) 2016/679 — "GDPR") and the French Loi Informatique et Libertés.

1. Data controller

The data controller is NAVIGATING FRANCE, registered at VALLAURIS, FRANCE, registration ‭899 691 224‬. Contact for any privacy matter: hello@navigatingfrance.com.

We have appointed NAVIGATING FRANCE as the point of contact for data protection. If we do not respond to a request within 30 days, you may lodge a complaint with the French supervisory authority, the CNIL.

2. What data we collect

  • Account data: email, name, password hash, authentication provider identifier (e.g. Google sub), sign-in timestamps and IP address for security.
  • Profile data you provide: nationality, family situation, arrival date, visa type, address in France, fields used to tailor the checklist (you control what you enter).
  • Checklist & document data: task progress, notes, uploaded files (administrative documents you choose to store), translations you generate.
  • Payment data: subscription tier, customer ID, invoice metadata. Card details are handled exclusively by Stripe — we never see or store them.
  • Usage data: pages visited, feature interactions, error logs. Analytics cookies are only set if you consent (see Cookie Policy).
  • Assistant inputs: the questions and context you submit to the Navigating France assistant, and the responses returned, retained to provide the service and improve quality.

3. Purposes and legal bases (Art. 6 GDPR)

  • Providing the service, account, and checklist — performance of a contract.
  • Processing subscription payments and issuing invoices — contract and legal obligation (French accounting rules).
  • Security, fraud prevention, audit logs — legitimate interest.
  • Product analytics and marketing cookies — your consent, freely withdrawable.
  • Customer support and service emails — contract.
  • Optional product updates / newsletter — your consent, with one-click unsubscribe.

4. Who we share data with (processors)

We share personal data only with vetted sub-processors acting on our instructions under Article 28 GDPR:

  • Supabase — managed database, authentication, file storage (EU region).
  • Stripe — payment processing (PCI-DSS).
  • Cloudflare — hosting, edge runtime, DDoS protection.
  • Language-model providers — execution of assistant prompts.
  • Our email delivery provider — transactional and account emails.

A current sub-processor list is available on request. Where a processor is outside the EU/EEA, transfers rely on the European Commission's Standard Contractual Clauses and supplementary measures.

5. Retention

  • Account & profile data — kept while your account is active and 12 months after deletion (for legal claims), then erased.
  • Documents you upload — kept until you delete them or close your account.
  • Invoices & payment records — 10 years (French Commercial Code, Art. L123-22).
  • Security logs — 12 months.
  • Cookie consent records — 13 months (CNIL guidance).

6. Your rights

Under Articles 15–22 GDPR you can, at any time:

  • Access the personal data we hold about you.
  • Rectify inaccurate data.
  • Erase your data ("right to be forgotten") subject to legal retention.
  • Restrict or object to processing based on legitimate interest.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time without affecting prior lawful processing.
  • Set instructions on the fate of your data after death (Loi Informatique et Libertés, Art. 85).

Submit any request via our Data request form or by email to hello@navigatingfrance.com. We respond within one month (extendable to three for complex requests).

7. Security

We apply industry-standard security: TLS in transit, encryption at rest, row-level access control, least-privilege service accounts, regular dependency scans, and incident response procedures. In the event of a personal data breach likely to result in a risk to your rights, we notify the CNIL within 72 hours and inform affected users without undue delay, in line with Articles 33–34 GDPR.

8. Children

The service is intended for adults handling French administrative procedures. We do not knowingly collect data from children under 15. If you believe a minor has registered, contact us and we will erase the account.

9. Changes

We may update this policy. Material changes will be announced in-app or by email at least 30 days before they take effect.